temporal-cloud-setup

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses a central executor script scripts/provision.sh to perform operations. It invokes standard development tools such as git, brew, npm, pip, mvn, and the temporal CLI. These commands are disclosed to the user before execution as part of a 'gate' mechanism.
  • [EXTERNAL_DOWNLOADS]: The skill downloads the Temporal Cloud CLI via Homebrew (temporalio/prerelease/temporal-cloud) and clones sample repositories from the official temporalio GitHub organization. These are verified vendor resources for the 'temporalio' author.
  • [CREDENTIALS_UNSAFE]: The skill manages Temporal Cloud API keys. It employs a 'secret-handling carve-out' logic in scripts/provision.sh that uses temporary 0600 files and JSON redirection to ensure API tokens never reach standard output, logs, or the AI's context. The tokens are stored locally in a locked temporal.toml file with restricted permissions (chmod 600). No hardcoded secrets are present in the skill files; placeholders and redaction patterns are used throughout instructions.
  • [SAFE]: All external resources (GitHub repos, Homebrew taps, and API endpoints like *.tmprl.cloud) are official infrastructure belonging to the author, Temporal Technologies. The execution is scoped to the primary purpose of setting up their cloud service.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:29 PM