github-repokit-actions

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill configures Terragrunt to download a Terraform module from the author's GitHub repository.
  • Evidence: terraform { source = "git::https://github.com/emrecavunt/github-repokit.git//modules/github-repository?ref=v1.0.0" } in assets/bootstrap/github/actions/terragrunt.hcl and references/module-interface.md.
  • [COMMAND_EXECUTION]: The skill instructions and documentation guide the user or agent to run infrastructure management commands.
  • Evidence: make tg-plan and make apply in assets/bootstrap/github/actions/README.md. The skill specifically instructs the agent to "Print plan commands. Stop. Do not apply." in SKILL.md to ensure human oversight.
  • [DATA_EXPOSURE]: The skill requires standard authentication tokens and cloud identifiers, which are managed via local environment variables.
  • Evidence: Instructions to export GITHUB_TOKEN, AWS_ROLE_ARN, and GCP_WORKLOAD_IDENTITY_PROVIDER are provided as standard operational procedures in assets/bootstrap/github/actions/README.md and assets/bootstrap/github/actions/terragrunt.hcl.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 08:33 PM
Security Audit — agent-trust-hub — github-repokit-actions