ci-github-actions

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides documentation and configuration examples for establishing a PHP CI environment using GitHub Actions. It does not include any executable code or scripts within the skill folder.
  • [SAFE]: All referenced third-party actions (e.g., shivammathur/setup-php, ramsey/composer-install, and actions/checkout) are well-known, established tools within the GitHub Actions ecosystem.
  • [SAFE]: The skill explicitly promotes security best practices, such as pinning actions to specific versions or commit SHAs to mitigate supply-chain risks and explaining the safe handling of repository secrets in pull requests from forks.
  • [SAFE]: No obfuscation, data exfiltration patterns, or malicious prompt injection attempts were detected in the instructions or metadata.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 04:16 PM
Security Audit — agent-trust-hub — ci-github-actions