github-actions-pipeline-builder

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary function is to provide guidance and tools for CI/CD pipeline construction. All components, including scripts and templates, are consistent with this purpose.
  • [COMMAND_EXECUTION]: The skill provides utility scripts (action_usage_analyzer.ts and workflow_validator.ts) designed to be executed via the Bash tool. These scripts perform local file system operations (reading and parsing YAML workflows) which are legitimate for validating configurations and checking for outdated dependencies.
  • [EXTERNAL_DOWNLOADS]: The documentation and templates reference official GitHub Actions (e.g., actions/checkout, actions/setup-node) and trusted third-party integrations (e.g., codecov/codecov-action, slackapi/slack-github-action). All external references target well-known services or trusted organizations.
  • [CREDENTIALS_UNSAFE]: The skill actively promotes secure secret management. It identifies hardcoded credentials as an anti-pattern and provides clear instructions on using GitHub Secrets (${{ secrets.TOKEN }}). Placeholders used in documentation (e.g., sk-...) are benign examples.
  • [INDIRECT_PROMPT_INJECTION]: The provided validation scripts ingest local YAML files. While this represents a data ingestion surface, the scripts use standard parsing libraries and do not perform unsafe interpolation or execution of the data content. The attack surface is minimal and appropriate for the skill's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 12:13 AM
Security Audit — agent-trust-hub — github-actions-pipeline-builder