cofounder-app-deploy

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill manages sensitive data securely by instructing the agent to use GitHub Secrets (gh secret set) and avoid exposing secret values in chat sessions or log files.
  • [SAFE]: All external infrastructure operations are handled through official vendor workflows (locaweb/locaweb-cloud-provision) and well-known services (GitHub Actions, GHCR).
  • [SAFE]: Software dependencies are limited to standard, reputable packages such as the Kamal Ruby gem and the python-dotenv library.
  • [SAFE]: The skill includes a local utility script (scripts/generate_pg_cmd.py) for deterministic configuration of database parameters based on VM sizes, with no suspicious side effects.
  • [SAFE]: Network activities are limited to legitimate deployment tasks, such as performing health checks on the deployed application's public IP using nip.io domains.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 01:31 PM
Security Audit — agent-trust-hub — cofounder-app-deploy