insideout

Pass

Audited by Gen Agent Trust Hub on Mar 31, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill connects to a remote MCP server at https://app.luthersystems.com/v1/insideout-mcp for infrastructure design and management. This server is operated by the vendor (Luther Systems) and follows a session-isolated architecture.\n- [SAFE]: Cloud credentials are never handled directly by the skill or the agent. Authentication is performed via a browser-based OAuth flow directly with the cloud provider (AWS/GCP), which is a standard security best practice.\n- [SAFE]: The skill defines strict user confirmation gates for all high-impact actions, including Terraform generation, infrastructure deployment, and resource destruction, ensuring the user retains ultimate authority.\n- [SAFE]: Project context shared with the remote server is limited to non-sensitive metadata. The skill's instructions require the agent to generate a summary, exclude all secrets and source code, and obtain explicit user approval before any data is transmitted.\n- [SAFE]: Includes an optional maintenance script (scripts/snyk-scan.sh) that facilitates local security auditing using the trusted Snyk scanning tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 31, 2026, 01:59 AM