discover-environment

Pass

Audited by Gen Agent Trust Hub on Apr 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs cloud discovery using official and well-known libraries such as boto3, google-cloud-sdk, and azure-mgmt, which are trusted sources for interacting with cloud provider APIs.
  • [SAFE]: Credential management is handled through standard environment variables, AWS profiles, or default cloud identities; no hardcoded secrets, API keys, or unsafe storage practices were found.
  • [SAFE]: Configuration file parsing is implemented securely using yaml.safe_load() in src/discover.py, which prevents potential YAML deserialization attacks.
  • [SAFE]: No unauthorized network exfiltration or suspicious external connections were detected. The skill outputs the security graph locally to stdout or a user-specified file.
  • [SAFE]: The skill correctly implements a read-only architecture, requesting and utilizing only audit-level permissions (e.g., SecurityAudit, Viewer, Reader) to ensure it cannot mutate cloud state.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 20, 2026, 01:17 AM
Security Audit — agent-trust-hub — discover-environment