opentofu-skill-gcp

Pass

Audited by Gen Agent Trust Hub on Apr 8, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The utility script scripts/qa_runner.py utilizes subprocess.run to execute standard infrastructure-as-code and security tools including tofu, tflint, trivy, and checkov. These executions are performed using static command lists and are essential to the skill's functionality for code validation and security scanning.
  • [EXTERNAL_DOWNLOADS]: The documentation provides instructions for installing well-known and trusted security tools such as Trivy (from Aqua Security) and Checkov (from Bridgecrew/Prisma Cloud). These references target official and established technology providers.
  • [SAFE]: The skill demonstrates a strong security posture by encouraging the use of GCP KMS for state encryption, Secret Manager for credentials, and least-privilege IAM roles. The provided templates follow industry best practices for Google Cloud infrastructure.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 8, 2026, 07:22 PM
Security Audit — agent-trust-hub — opentofu-skill-gcp