skills/simota/agent-skills/ledger/Gen Agent Trust Hub

ledger

Pass

Audited by Gen Agent Trust Hub on Apr 25, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill integrates with Infracost via GitHub Actions (infracost/actions/setup) to perform cost estimation on IaC files. This is a well-known service commonly used for FinOps automation and is considered a safe external dependency.
  • [COMMAND_EXECUTION]: Provides templates and documentation for shell commands involving Infracost, jq, and bc for use within CI/CD pipelines. These commands are intended for the user to implement in their own environment for cost gating and are not executed by the skill itself in an unsafe manner.
  • [DATA_EXPOSURE]: The skill is designed to process Infrastructure-as-Code (IaC) resource definitions and cloud utilization metrics (CPU, Memory, GPU). This data ingestion is required for its stated purpose of cloud cost optimization and does not involve accessing sensitive user credentials or private keys.
  • [PROMPT_INJECTION]: No evidence of instructions attempting to bypass safety filters, override agent behavior, or extract system prompts was found. The instructions use standard pedagogical and operational language.
  • [DATA_EXFILTRATION]: No unauthorized network operations or exfiltration patterns were identified. The skill's architecture focuses on generating recommendations and configuration specifications to be passed to other agents or human operators.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 25, 2026, 12:03 PM