devsecops-pipeline
Pass
Audited by Gen Agent Trust Hub on May 9, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references a remote installation script for
syftfrom Anchore's official GitHub repository. Anchore is a well-known organization specializing in software supply chain security, and the use of this script is a standard installation method for the tool. - [COMMAND_EXECUTION]: The skill performs shell-based inspection of the local environment to detect repository structures (e.g., searching for
.github/workflows,Dockerfile, orterraform/directories) and existing CI configurations to generate a maturity assessment. - [SAFE]: The generated CI/CD templates in
REFERENCE.mdutilize official GitHub Actions and Docker images from established security vendors and open-source projects, including Aqua Security (Trivy), Bridgecrew (Checkov), and the Sigstore project (Cosign).
Audit Metadata