opentofu-skill-gcp
Pass
Audited by Gen Agent Trust Hub on Apr 8, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The utility script
scripts/qa_runner.pyutilizessubprocess.runto execute standard infrastructure-as-code and security tools includingtofu,tflint,trivy, andcheckov. These executions are performed using static command lists and are essential to the skill's functionality for code validation and security scanning. - [EXTERNAL_DOWNLOADS]: The documentation provides instructions for installing well-known and trusted security tools such as Trivy (from Aqua Security) and Checkov (from Bridgecrew/Prisma Cloud). These references target official and established technology providers.
- [SAFE]: The skill demonstrates a strong security posture by encouraging the use of GCP KMS for state encryption, Secret Manager for credentials, and least-privilege IAM roles. The provided templates follow industry best practices for Google Cloud infrastructure.
Audit Metadata