enabling-cmek-encryption
Pass
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the user or agent to execute shell commands using standard CLI tools including
ccloud,aws,gcloud, andaz. These operations are strictly for managing database infrastructure and encryption settings, aligning with the skill's stated purpose. - [DATA_EXFILTRATION]: No unauthorized data access or exfiltration patterns were identified. Network operations are directed towards official cloud provider endpoints (Amazon Web Services, Google Cloud Platform, Microsoft Azure) and CockroachDB Cloud APIs.
- [PROMPT_INJECTION]: The instructions are clear and follow standard operational procedures. There are no attempts to bypass safety filters, override system instructions, or hide malicious intent within the prompt text.
- [EXTERNAL_DOWNLOADS]: The skill does not perform any external package installations or remote script downloads. It relies on the presence of established system tools.
Audit Metadata