temporal-cloud-setup
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses a central executor script
scripts/provision.shto perform operations. It invokes standard development tools such asgit,brew,npm,pip,mvn, and thetemporalCLI. These commands are disclosed to the user before execution as part of a 'gate' mechanism. - [EXTERNAL_DOWNLOADS]: The skill downloads the Temporal Cloud CLI via Homebrew (
temporalio/prerelease/temporal-cloud) and clones sample repositories from the officialtemporalioGitHub organization. These are verified vendor resources for the 'temporalio' author. - [CREDENTIALS_UNSAFE]: The skill manages Temporal Cloud API keys. It employs a 'secret-handling carve-out' logic in
scripts/provision.shthat uses temporary 0600 files and JSON redirection to ensure API tokens never reach standard output, logs, or the AI's context. The tokens are stored locally in a lockedtemporal.tomlfile with restricted permissions (chmod 600). No hardcoded secrets are present in the skill files; placeholders and redaction patterns are used throughout instructions. - [SAFE]: All external resources (GitHub repos, Homebrew taps, and API endpoints like
*.tmprl.cloud) are official infrastructure belonging to the author, Temporal Technologies. The execution is scoped to the primary purpose of setting up their cloud service.
Audit Metadata