github-actions

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No attempts to override agent behavior or extract system prompts were detected. The instructions focus on guiding the user through CI/CD best practices.- [DATA_EXFILTRATION]: No unauthorized data access or exfiltration patterns were found. The skill correctly instructs users to use the GitHub secrets context and OIDC for sensitive information and cloud authentication.- [REMOTE_CODE_EXECUTION]: No malicious remote code execution patterns. The skill actively encourages pinning third-party actions to immutable commit SHAs to prevent supply chain attacks.- [COMMAND_EXECUTION]: The provided shell commands and workflow examples (using tools like gh, act, and actionlint) are standard for CI/CD operations, validation, and local testing.- [SAFE]: The skill exclusively references trusted repositories from organizations such as GitHub and AWS, and provides guidance consistent with official security documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 12:23 AM
Security Audit — agent-trust-hub — github-actions