sota-devsecops

Pass

Audited by Gen Agent Trust Hub on Oct 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides defensive security rules for AI agents to follow when building or auditing software delivery pipelines. It explicitly identifies and provides mitigations for common supply chain attack vectors, including script injection in CI workflows, malicious PR code execution via pull_request_target, and dependency confusion. All external tools and services referenced (such as Sigstore, Cosign, Syft, Grype, and Opengrep) are well-known security industry standards or originate from trusted organizations. The instructions encourage least-privilege token usage, OIDC federation, and immutable artifact verification. No hidden code execution, obfuscation, or data exfiltration mechanisms were found within the skill's instructions or referenced rules files.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 4, 2026, 12:02 AM
Security Audit — agent-trust-hub — sota-devsecops