Deployment Automation

Pass

Audited by Gen Agent Trust Hub on Feb 24, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill employs localized shell scripts (e.g., release-orchestrator.sh and pre-flight-check.sh) to automate complex deployment workflows, including building packages with bun and nix and managing releases via the GitHub CLI.
  • [EXTERNAL_DOWNLOADS]: It references official Holochain and Lair binaries with hardcoded SHA256 checksums to ensure file integrity during environment setup.
  • [EXTERNAL_DOWNLOADS]: The skill utilizes well-known technology services, including STUN servers from Google and Cloudflare for WebRTC, and official GitHub Actions for repository orchestration.
  • [SAFE]: No hardcoded credentials or malicious obfuscation patterns were detected. Sensitive data like deployment certificates is managed through industry-standard secret management in GitHub Actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 24, 2026, 02:44 PM