publish-models
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: Documents installing the developer tool
cog-safe-pushfrom Replicate's official GitHub repository (replicate/cog-safe-push). This is a legitimate tool belonging to the author vendor, adhering to vendor context rules. - [COMMAND_EXECUTION]: Outlines sample commands for using
cog push,cog-safe-push, and pipeline workflows, which are safe educational references for deployment infrastructure. - [CREDENTIALS_UNSAFE]: Uses environment variable injections (
$TOKEN,${{ secrets.REPLICATE_API_TOKEN }}) and explicit placeholders, following proper security best practices by advising never to commit actual keys.
Audit Metadata