github-actions-docs

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed purely to provide users with authoritative documentation links and YAML guidance based on official GitHub resources.
  • [EXTERNAL_DOWNLOADS]: The skill references content from docs.github.com, which is a well-known and trusted service for technical documentation.
  • [CREDENTIALS_UNSAFE]: Mentions of sensitive terms like GITHUB_TOKEN and Secrets are strictly referential, pointing to security hardening documentation rather than attempting to access or exfiltrate live environment variables.
  • [COMMAND_EXECUTION]: Inline backticks in SKILL.md are used for Markdown formatting of tool names (e.g., codeql, dependabot) and topic keywords, posing no risk of shell command injection or execution.
  • [INDIRECT_PROMPT_INJECTION]: While the skill processes user-supplied questions, it lacks the dangerous capabilities (such as file-writing, network exfiltration to unknown domains, or code execution) necessary to facilitate a successful injection attack.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 03:17 PM