devsecops-pipeline

Pass

Audited by Gen Agent Trust Hub on May 9, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references a remote installation script for syft from Anchore's official GitHub repository. Anchore is a well-known organization specializing in software supply chain security, and the use of this script is a standard installation method for the tool.
  • [COMMAND_EXECUTION]: The skill performs shell-based inspection of the local environment to detect repository structures (e.g., searching for .github/workflows, Dockerfile, or terraform/ directories) and existing CI configurations to generate a maturity assessment.
  • [SAFE]: The generated CI/CD templates in REFERENCE.md utilize official GitHub Actions and Docker images from established security vendors and open-source projects, including Aqua Security (Trivy), Bridgecrew (Checkov), and the Sigstore project (Cosign).
Audit Metadata
Risk Level
SAFE
Analyzed
May 9, 2026, 02:07 AM
Security Audit — agent-trust-hub — devsecops-pipeline