discover-environment
Pass
Audited by Gen Agent Trust Hub on Apr 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill performs cloud discovery using official and well-known libraries such as boto3, google-cloud-sdk, and azure-mgmt, which are trusted sources for interacting with cloud provider APIs.
- [SAFE]: Credential management is handled through standard environment variables, AWS profiles, or default cloud identities; no hardcoded secrets, API keys, or unsafe storage practices were found.
- [SAFE]: Configuration file parsing is implemented securely using yaml.safe_load() in src/discover.py, which prevents potential YAML deserialization attacks.
- [SAFE]: No unauthorized network exfiltration or suspicious external connections were detected. The skill outputs the security graph locally to stdout or a user-specified file.
- [SAFE]: The skill correctly implements a read-only architecture, requesting and utilizing only audit-level permissions (e.g., SecurityAudit, Viewer, Reader) to ensure it cannot mutate cloud state.
Audit Metadata