maintainx-deploy-integration
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFE
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill avoids hardcoding sensitive information. It correctly demonstrates the use of platform-specific secret management tools (Google Secret Manager, Kubernetes Secrets) to handle the MAINTAINX_API_KEY.
- [EXTERNAL_DOWNLOADS]: Fetches official Docker images and GitHub Actions from recognized providers like Google. These downloads are documented neutrally as they originate from trusted, well-known services.
- [INDIRECT_PROMPT_INJECTION]: The skill has a minimal attack surface for indirect injection, as it primarily handles local deployment scripts and performs health checks against a specific API client.
Audit Metadata