publish-models

Pass

Audited by Gen Agent Trust Hub on May 5, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches the cog-safe-push utility from the vendor's official GitHub repository (github.com/replicate/cog-safe-push). This is a standard installation procedure for the tool described.
  • [COMMAND_EXECUTION]: Outlines the use of CLI tools for model lifecycle management, including building, pushing, and validating models via cog and cog-safe-push.
  • [DATA_EXFILTRATION]: Specifically advises users against hardcoding sensitive credentials like REPLICATE_API_TOKEN and ANTHROPIC_API_KEY, directing the use of environment variables and platform-specific secrets (e.g., GitHub Actions secrets) instead.
Audit Metadata
Risk Level
SAFE
Analyzed
May 5, 2026, 09:59 PM