implementing-zero-trust-in-cloud
Pass
Audited by Gen Agent Trust Hub on Apr 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill utilizes official and well-known cloud SDKs (boto3, azure-identity, google-cloud-compute) from trusted vendors for its assessment functionality.
- [SAFE]: Analysis of
scripts/agent.pyconfirms it only performs read-only operations against cloud APIs to evaluate security posture and does not exfiltrate data to external domains. - [SAFE]: The
SKILL.mddocumentation uses standard placeholders for configuration values (e.g.,verified-access-client-secret) without hardcoding actual credentials. - [SAFE]: All external references and URLs point to official government (NIST, CISA) or major cloud provider (Google, AWS, Microsoft) documentation.
Audit Metadata