cofounder-app-deploy
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill manages sensitive data securely by instructing the agent to use GitHub Secrets (
gh secret set) and avoid exposing secret values in chat sessions or log files. - [SAFE]: All external infrastructure operations are handled through official vendor workflows (
locaweb/locaweb-cloud-provision) and well-known services (GitHub Actions, GHCR). - [SAFE]: Software dependencies are limited to standard, reputable packages such as the Kamal Ruby gem and the
python-dotenvlibrary. - [SAFE]: The skill includes a local utility script (
scripts/generate_pg_cmd.py) for deterministic configuration of database parameters based on VM sizes, with no suspicious side effects. - [SAFE]: Network activities are limited to legitimate deployment tasks, such as performing health checks on the deployed application's public IP using nip.io domains.
Audit Metadata