cicd-security

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute local shell scripts (tools/cicd_scanner.sh, tools/secrets_hunter.sh, install_tools.sh) and standard CLI utilities (grep, gh, nslookup) to perform security audits and reconnaissance on target repositories.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external data from GitHub repositories, such as Pull Request titles, bodies, and workflow configurations. It provides patterns for identifying and exploiting indirect injection surfaces within CI/CD pipelines.
  • [EXTERNAL_DOWNLOADS]: The skill references the installation of well-known third-party security tools including trufflehog, gitleaks, and nuclei via an installation script, as well as the gh CLI tool through official package managers (Homebrew).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 10:34 AM
Security Audit — agent-trust-hub — cicd-security