truefoundry-prompts

Pass

Audited by Gen Agent Trust Hub on Apr 19, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes local shell scripts (scripts/tfy-api.sh and scripts/tfy-version.sh) to interact with the TrueFoundry platform via curl and detect the local installation status of required tools like the tfy CLI and the truefoundry Python SDK.
  • [EXTERNAL_DOWNLOADS]: The documentation references the official truefoundry Python package and various container images hosted on AWS ECR, JFrog, and GitHub Container Registry (GHCR). All mentioned resources belong to the vendor (TrueFoundry) or well-known services (HuggingFace).
  • [SAFE]: The skill incorporates security warnings regarding the ingestion of untrusted prompt text and mandates the use of secret references (tfy-secret://) for sensitive information in deployment manifests instead of hardcoding credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 19, 2026, 11:52 PM