sota-cloud-infrastructure

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No attempts to override agent behavior, bypass safety guidelines, or extract system prompts were detected. The instructions use standard pedagogical and technical formatting.- [DATA_EXFILTRATION]: No sensitive file path access, hardcoded credentials, or unauthorized network operations were found. IAM and resource policy examples correctly use documentation placeholders (e.g., dummy account IDs like 111122223333).- [REMOTE_CODE_EXECUTION]: The skill does not perform or suggest downloading and executing arbitrary scripts. It references established infrastructure-as-code and FinOps tools like Terraform, Infracost, and OpenCost in a purely architectural context.- [COMMAND_EXECUTION]: There are no dangerous shell commands or attempts to gain unauthorized system access. Instructions focus on producing static configuration fragments.- [SAFE]: The skill is a well-structured knowledge base for cloud security. It includes exhaustive checklists and non-negotiable security rules that align with industry standards for landing zones, identity federation, and data protection.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 10:17 PM
Security Audit — agent-trust-hub — sota-cloud-infrastructure