github-actions-docs
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is designed purely to provide users with authoritative documentation links and YAML guidance based on official GitHub resources.
- [EXTERNAL_DOWNLOADS]: The skill references content from
docs.github.com, which is a well-known and trusted service for technical documentation. - [CREDENTIALS_UNSAFE]: Mentions of sensitive terms like
GITHUB_TOKENandSecretsare strictly referential, pointing to security hardening documentation rather than attempting to access or exfiltrate live environment variables. - [COMMAND_EXECUTION]: Inline backticks in
SKILL.mdare used for Markdown formatting of tool names (e.g.,codeql,dependabot) and topic keywords, posing no risk of shell command injection or execution. - [INDIRECT_PROMPT_INJECTION]: While the skill processes user-supplied questions, it lacks the dangerous capabilities (such as file-writing, network exfiltration to unknown domains, or code execution) necessary to facilitate a successful injection attack.
Audit Metadata