ci-github-actions
Pass
Audited by Gen Agent Trust Hub on Jul 3, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides documentation and configuration examples for establishing a PHP CI environment using GitHub Actions. It does not include any executable code or scripts within the skill folder.
- [SAFE]: All referenced third-party actions (e.g.,
shivammathur/setup-php,ramsey/composer-install, andactions/checkout) are well-known, established tools within the GitHub Actions ecosystem. - [SAFE]: The skill explicitly promotes security best practices, such as pinning actions to specific versions or commit SHAs to mitigate supply-chain risks and explaining the safe handling of repository secrets in pull requests from forks.
- [SAFE]: No obfuscation, data exfiltration patterns, or malicious prompt injection attempts were detected in the instructions or metadata.
Audit Metadata