ci-pipelines
Pass
Audited by Gen Agent Trust Hub on Aug 4, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill exclusively contains markdown documentation and YAML configuration examples for GitHub Actions. It does not include executable scripts, binary files, or network-enabled tools.
- [SAFE]: All external references target well-known and trusted entities, specifically the official
actions/andaws-actions/GitHub organizations, which are standard for the described use case. - [SAFE]: The skill actively promotes security best practices, such as pinning actions by commit SHA, using OIDC for cloud credentials instead of long-lived secrets, and implementing least-privilege permissions (
id-token: write). - [SAFE]: No obfuscation, data exfiltration patterns, or persistence mechanisms were detected. The skill's content is consistent with its stated purpose of improving CI pipeline efficiency and correctness.
Audit Metadata