skills/tonone-ai/tonone/forge-infra/Gen Agent Trust Hub

forge-infra

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill explicitly promotes security best practices in its instructions, such as mandating least-privilege IAM roles, preventing hardcoded secrets, and enforcing HTTPS/firewall defaults.
  • [COMMAND_EXECUTION]: The skill uses standard CLI tools (find, ls, cat) and cloud CLIs (aws, gcloud) to gather project context. This is appropriate for its stated purpose of building infrastructure as code and ensuring resources are deployed to the correct environment.
  • [DATA_EXPOSURE]: While the skill reads project metadata (account IDs, project IDs, and configuration files), these actions are necessary for the primary function of infrastructure management and do not involve exfiltration to external domains.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 02:47 PM
Security Audit — agent-trust-hub — forge-infra