github-actions
Pass
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: No attempts to override agent behavior or extract system prompts were detected. The instructions focus on guiding the user through CI/CD best practices.- [DATA_EXFILTRATION]: No unauthorized data access or exfiltration patterns were found. The skill correctly instructs users to use the GitHub secrets context and OIDC for sensitive information and cloud authentication.- [REMOTE_CODE_EXECUTION]: No malicious remote code execution patterns. The skill actively encourages pinning third-party actions to immutable commit SHAs to prevent supply chain attacks.- [COMMAND_EXECUTION]: The provided shell commands and workflow examples (using tools like gh, act, and actionlint) are standard for CI/CD operations, validation, and local testing.- [SAFE]: The skill exclusively references trusted repositories from organizations such as GitHub and AWS, and provides guidance consistent with official security documentation.
Audit Metadata