github-actions-pipeline-hardened

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill promotes supply chain security by mandating that all GitHub Actions references are pinned to full commit SHAs instead of floating tags.
  • [SAFE]: It implements the principle of least privilege by defaulting workflow permissions to 'read-all' and requiring explicit, job-level overrides for necessary write access.
  • [SAFE]: The process encourages the use of OIDC (OpenID Connect) for cloud provider authentication, which eliminates the security risk associated with storing long-lived, static credentials in repository secrets.
  • [SAFE]: The skill incorporates security scanning tools (SAST and dependency scanning) and artifact verification (SBOM generation and container signing with cosign) as integral parts of the generated pipeline.
  • [SAFE]: No obfuscation, data exfiltration, malicious persistence, or unauthorized command execution patterns were detected in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 08:35 AM
Security Audit — agent-trust-hub — github-actions-pipeline-hardened