github-actions-pipeline-hardened
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill promotes supply chain security by mandating that all GitHub Actions references are pinned to full commit SHAs instead of floating tags.
- [SAFE]: It implements the principle of least privilege by defaulting workflow permissions to 'read-all' and requiring explicit, job-level overrides for necessary write access.
- [SAFE]: The process encourages the use of OIDC (OpenID Connect) for cloud provider authentication, which eliminates the security risk associated with storing long-lived, static credentials in repository secrets.
- [SAFE]: The skill incorporates security scanning tools (SAST and dependency scanning) and artifact verification (SBOM generation and container signing with cosign) as integral parts of the generated pipeline.
- [SAFE]: No obfuscation, data exfiltration, malicious persistence, or unauthorized command execution patterns were detected in the instructions.
Audit Metadata