devops-deployment
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFE
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes shell execution placeholders (
!command) withinscripts/create-ci-pipeline.mdandscripts/create-docker-compose.mdto perform local environment discovery. These commands (such asgrep,ls, andtest) are used to detect project types, language versions, and service configurations in order to populate generated templates. The implementation is benign and focused on providing contextual automation. - [EXTERNAL_DOWNLOADS]: The skill provides numerous links to external documentation. All referenced domains (e.g., github.com, kubernetes.io, terraform.io, helm.sh, railway.com) are well-known, trusted technology services and organizations. These references are used for informational purposes and do not involve remote code execution from untrusted sources.
- [CREDENTIALS_UNSAFE]: While static analysis flagged hardcoded connection strings in
scripts/docker-compose.yml, these were found to be standard boilerplate credentials (e.g.,postgres:postgres) intended for local development environments. They do not constitute a leak of sensitive production secrets and follow standard local development practices.
Audit Metadata