deployment-pipeline-design
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides documentation and templates for designing CI/CD pipelines using standard industry tools such as GitHub Actions, GitLab CI, Azure Pipelines, and Argo Rollouts.
- [SAFE]: Hardcoded credentials found (e.g.,
POSTGRES_PASSWORD: test) are standard placeholders for ephemeral CI testing environments and do not represent a risk to production systems. - [SAFE]: All external actions and tools referenced (e.g.,
aquasecurity/trivy-action,semgrep/semgrep-action,aws-actions/configure-aws-credentials) are official, well-known, and follow security best practices like OIDC authentication. - [SAFE]: The skill emphasizes safety patterns such as backward-compatible database migrations, automated rollbacks, and deep health checks to ensure production stability.
Audit Metadata