cicd-security
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute local shell scripts (
tools/cicd_scanner.sh,tools/secrets_hunter.sh,install_tools.sh) and standard CLI utilities (grep,gh,nslookup) to perform security audits and reconnaissance on target repositories. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external data from GitHub repositories, such as Pull Request titles, bodies, and workflow configurations. It provides patterns for identifying and exploiting indirect injection surfaces within CI/CD pipelines.
- [EXTERNAL_DOWNLOADS]: The skill references the installation of well-known third-party security tools including
trufflehog,gitleaks, andnucleivia an installation script, as well as theghCLI tool through official package managers (Homebrew).
Audit Metadata