implementing-infrastructure-as-code-security-scanning

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides instructions for implementing security best practices using well-established open-source tools and official platforms.
  • [EXTERNAL_DOWNLOADS]: The skill references resources and tools from well-known technology companies and security organizations:
  • Installation of the checkov utility from its official source via pip.
  • Integration with GitHub Actions from reputable vendors including bridgecrewio (Palo Alto Networks), aquasecurity, and github.
  • Usage of the checkmarx/kics security scanner through its official Docker container image.
  • [COMMAND_EXECUTION]: The skill includes example shell commands for running infrastructure scans using checkov, terraform, and docker. These commands are standard for the intended DevSecOps workflow and do not exhibit any malicious patterns or unauthorized operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 05:09 AM
Security Audit — agent-trust-hub — implementing-infrastructure-as-code-security-scanning