twingate-pulumi

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references the installation of the Twingate Pulumi provider through official package registries (NPM, PyPI, Go) and the deployment of connectors via the vendor's setup scripts from binaries.twingate.com. These are expected behaviors for an IaC support skill using official vendor resources.\n- [COMMAND_EXECUTION]: The skill documents the execution of standard infrastructure and development CLI tools, including pulumi, npm, pip, and the act utility for local GitHub Action testing. These tools are used within their intended functional scope for environment provisioning and development.\n- [INDIRECT_PROMPT_INJECTION]: The skill is instructed to read local Pulumi configuration and resource files (such as twingate.RemoteNetwork and twingate.Connector) to ensure new code matches existing patterns. While this involves processing local file content, the scope is limited to technical infrastructure definitions, and the skill provides clear directives to handle sensitive outputs safely.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 09:19 PM
Security Audit — agent-trust-hub — twingate-pulumi