ci-cd-and-automation

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill establishes robust quality gates, specifically incorporating npm audit with an audit level of 'high' to detect and prevent known vulnerabilities in dependencies.
  • [SAFE]: It mandates the use of environment variable secrets (e.g., ${{ secrets.CI_DB_PASSWORD }} and ${{ secrets.VERCEL_TOKEN }}) instead of hardcoding credentials, adhering to security best practices for CI/CD environments.
  • [SAFE]: The workflows utilize official GitHub Actions (actions/checkout, actions/setup-node) and well-known industry tools (playwright, vercel), which are recognized as trusted and well-known services.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 08:43 AM
Security Audit — agent-trust-hub — ci-cd-and-automation