devops-deploy
Pass
Audited by Gen Agent Trust Hub on Apr 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides standard, well-documented templates for DevOps workflows, Docker configurations, and AWS infrastructure without any malicious patterns or hidden instructions.
- [CREDENTIALS_UNSAFE]: The documentation explicitly encourages best practices for secret management, demonstrating the use of environment variables and dedicated services like AWS Secrets Manager and GitHub Secrets rather than hardcoding sensitive information.
- [EXTERNAL_DOWNLOADS]: The CI/CD workflow example includes a notification step that sends status updates to Telegram's public API; this is a common and legitimate use of a well-known service for infrastructure monitoring.
- [COMMAND_EXECUTION]: Shell commands included in the skill (such as docker, sam, and pip) are necessary for the declared DevOps purpose and are used according to standard development practices.
Audit Metadata