temporal-serverless
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: Downloads SDK packages and build artifacts from official registries like NuGet, Maven Central, npm, and PyPI. It also references official Temporal sample repositories on GitHub. These actions are necessary for the primary function of building and deploying workers.
- [COMMAND_EXECUTION]: Instructs the agent to execute AWS CLI and Temporal CLI commands to provision cloud resources and manage worker deployments. All mutating operations require explicit user approval and follow a structured deployment workflow.
- [CREDENTIALS_UNSAFE]: Handles Temporal API keys via environment variables for deployment. The skill documentation explicitly warns against hardcoding secrets and provides guidance on using AWS Secrets Manager for production environments to ensure secure credential handling.
- [INDIRECT_PROMPT_INJECTION]: Ingests user-supplied parameters such as Namespace names and resource prefixes. The skill incorporates boundary checks, validates names against cloud providers, and prints a final resource inventory for user review to mitigate injection risks.
Audit Metadata