github-actions-author
Pass
Audited by Gen Agent Trust Hub on May 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's primary function is to provide structured guidance and templates for GitHub Actions development.
- [SAFE]: All examples and templates utilize legitimate, SHA-pinned references to official GitHub Actions and trusted cloud provider tools (e.g., AWS, GCP, Azure).
- [SAFE]: The skill contains no executable code, obfuscated content, or patterns associated with prompt injection or credential theft.
- [SAFE]: The 'review' mode analyzes workflow configuration files solely for the purpose of generating a report and does not perform any restricted system operations or network exfiltration.
- [SAFE]: Security-centric rules (found in
rules/security.md) actively promote defensive configurations and warn against common supply-chain risks, such as mutable tags and unscoped triggers.
Audit Metadata