deployment-ci-cd
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill documents industry-standard CI/CD practices for multiple technology stacks including NestJS, Spring Boot, FastAPI, Angular, and Flutter.
- [SAFE]: It includes rigorous security checklists, specifically advocating for the use of Workload Identity Federation over service account keys, image scanning with tools like Trivy, and the enforcement of non-root users in Docker containers.
- [SAFE]: Code examples demonstrate secure environment variable handling using validation libraries (Zod, Pydantic) to ensure services fail fast if configurations are missing, preventing runtime errors in production.
- [SAFE]: No evidence of prompt injection, data exfiltration, obfuscation, or unauthorized command execution was detected in any of the provided files or reference materials.
Audit Metadata