temporal-cloud-setup

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill manages Temporal Cloud API keys using secure handling practices. The provision.sh script captures secrets into temporary files with restrictive 0600 permissions and writes them directly to a local configuration file, ensuring they are never exposed in terminal logs, shell history, or the agent's chat context.
  • [EXTERNAL_DOWNLOADS]: The skill downloads official Temporal components, including the Temporal CLI (via Homebrew) and sample repositories from the temporalio GitHub organization. These are verified vendor resources.
  • [COMMAND_EXECUTION]: All setup operations are performed via a deterministic provision.sh bash script. The skill enforces a 'disclosure-before-run' policy, ensuring the user sees the exact commands to be executed for transparency and control.
  • [INDIRECT_PROMPT_INJECTION]: The skill accepts user input for project configuration (SDK and directory paths). The implementation mitigates injection risks by using the user input solely for parameters in pre-defined command templates within the execution script.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 10:59 AM