implementing-zero-trust-in-cloud

Pass

Audited by Gen Agent Trust Hub on Apr 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill utilizes official and well-known cloud SDKs (boto3, azure-identity, google-cloud-compute) from trusted vendors for its assessment functionality.
  • [SAFE]: Analysis of scripts/agent.py confirms it only performs read-only operations against cloud APIs to evaluate security posture and does not exfiltrate data to external domains.
  • [SAFE]: The SKILL.md documentation uses standard placeholders for configuration values (e.g., verified-access-client-secret) without hardcoding actual credentials.
  • [SAFE]: All external references and URLs point to official government (NIST, CISA) or major cloud provider (Google, AWS, Microsoft) documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 20, 2026, 11:33 PM