truefoundry-monitor

Pass

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs standard deployment monitoring tasks using vendor-specific APIs and CLI tools. No suspicious or unauthorized operations were identified.- [SAFE]: Credential management follows industry best practices. The skill instructs users to store sensitive API keys in environment variables or .env files rather than hardcoding them within the skill or manifests.- [SAFE]: The skill includes proactive security guidance in 'references/container-versions.md', specifically warning against fetching and parsing content from untrusted third-party release pages to prevent indirect prompt injection attacks.- [SAFE]: The provided shell scripts, such as 'scripts/tfy-api.sh', implement basic input validation to prevent path traversal when constructing API requests.- [EXTERNAL_DOWNLOADS]: The skill includes instructions to install the 'truefoundry' CLI package from official registries (PyPI) and provides pinned versions for container images from trusted sources like Amazon ECR and GitHub Container Registry.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 1, 2026, 05:23 PM