implementing-infrastructure-as-code-security-scanning
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides instructions for implementing security best practices using well-established open-source tools and official platforms.
- [EXTERNAL_DOWNLOADS]: The skill references resources and tools from well-known technology companies and security organizations:
- Installation of the
checkovutility from its official source viapip. - Integration with GitHub Actions from reputable vendors including
bridgecrewio(Palo Alto Networks),aquasecurity, andgithub. - Usage of the
checkmarx/kicssecurity scanner through its official Docker container image. - [COMMAND_EXECUTION]: The skill includes example shell commands for running infrastructure scans using
checkov,terraform, anddocker. These commands are standard for the intended DevSecOps workflow and do not exhibit any malicious patterns or unauthorized operations.
Audit Metadata