zero-trust
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides educational documentation, configuration templates, and example commands for zero-trust security implementations. The content is strictly technical and follows industry best practices for modern security architecture.
- [COMMAND_EXECUTION]: The skill includes example
curlcommands for interacting with the Cloudflare API. These commands appropriately use environment variables (e.g.,${CF_TOKEN},${ACCOUNT_ID}) to handle sensitive credentials, which is the standard method for avoiding hardcoded secrets. - [REMOTE_CODE_EXECUTION]: The Kubernetes deployment templates reference a standard container image (
quay.io/oauth2-proxy/oauth2-proxy:v7.6.0) from a well-known public registry. This is an expected and routine practice for infrastructure-as-code and DevOps skills. - [INDIRECT_PROMPT_INJECTION]: The skill functions as a repository for templates and architectural guidance. It does not ingest or process untrusted external data during its execution context, minimizing the risk of indirect injection.
Audit Metadata