ci-maintenance

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and review GitHub Actions workflows and repository files, which represent untrusted external data. This surface is mitigated by instructions that explicitly mandate auditing trust boundaries, validating environment variables, and verifying identity/source of cross-run data.
  • [REMOTE_CODE_EXECUTION]: No remote code execution or untrusted downloads are performed by the skill. On the contrary, it enforces security by requiring that all external actions and reusable workflows be pinned to full commit SHAs rather than mutable tags or branches.
  • [CREDENTIALS_UNSAFE]: The skill does not contain hardcoded credentials. It includes specific rules for managing privileged workflows, emphasizing that jobs using secrets must not run untrusted code and must account for every write permission.
  • [SAFE]: The instructions align with industry-standard security benchmarks for CI/CD environments and do not include any obfuscation, privilege escalation, or persistence mechanisms.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 10:08 AM