infrastructure-blueprints

Warn

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: MEDIUMCREDENTIALS_UNSAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [CREDENTIALS_UNSAFE]: Hardcoded database and application credentials found within deployment blueprints.
  • company-software/twenty-crm.yaml: Contains hardcoded PostgreSQL credentials PG_DATABASE_URL=postgres://twenty:twenty@db:5432/default and POSTGRES_PASSWORD=twenty.
  • trading/trading-grafana.yaml: Uses a default fallback password changeme in GF_SECURITY_ADMIN_PASSWORD=${GRAFANA_ADMIN_PASSWORD:-changeme}.
  • [COMMAND_EXECUTION]: The skill defines complex deployment workflows intended to be executed through container and infrastructure management tools.
  • Instructions in SKILL.md guide the agent to use tools like portainer-mcp, technitium-dns-mcp, and graph-os to create stacks, manage DNS, and modify graph topologies.
  • [EXTERNAL_DOWNLOADS]: The blueprints reference and pull Docker images from external registries.
  • References official and community images for MariaDB, Redis, Grafana, ERPNext, Twenty CRM, and Freqtrade from Docker Hub.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 19, 2026, 01:36 PM
Security Audit — agent-trust-hub — infrastructure-blueprints