github-actions-pipeline-builder
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's primary function is to provide guidance and tools for CI/CD pipeline construction. All components, including scripts and templates, are consistent with this purpose.
- [COMMAND_EXECUTION]: The skill provides utility scripts (
action_usage_analyzer.tsandworkflow_validator.ts) designed to be executed via theBashtool. These scripts perform local file system operations (reading and parsing YAML workflows) which are legitimate for validating configurations and checking for outdated dependencies. - [EXTERNAL_DOWNLOADS]: The documentation and templates reference official GitHub Actions (e.g.,
actions/checkout,actions/setup-node) and trusted third-party integrations (e.g.,codecov/codecov-action,slackapi/slack-github-action). All external references target well-known services or trusted organizations. - [CREDENTIALS_UNSAFE]: The skill actively promotes secure secret management. It identifies hardcoded credentials as an anti-pattern and provides clear instructions on using GitHub Secrets (
${{ secrets.TOKEN }}). Placeholders used in documentation (e.g.,sk-...) are benign examples. - [INDIRECT_PROMPT_INJECTION]: The provided validation scripts ingest local YAML files. While this represents a data ingestion surface, the scripts use standard parsing libraries and do not perform unsafe interpolation or execution of the data content. The attack surface is minimal and appropriate for the skill's context.
Audit Metadata