github-actions

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill documents best practices for GitHub Actions, specifically addressing high-risk areas like the pull_request_target trigger and the importance of SHA-pinning to prevent supply-chain attacks (citing the 2025 tj-actions compromise as a case study).
  • [SAFE]: The provided verify.sh script is a read-only static analysis tool designed to detect common misconfigurations (e.g., missing permissions, unpinned third-party actions, or OIDC opportunities) without performing network operations or executing external code.
  • [SAFE]: References to external cloud providers (AWS, GCP, Azure) and first-party GitHub actions (actions/*, github/*) are treated as trusted/well-known services and are used exclusively to illustrate secure integration patterns.
  • [SAFE]: The skill correctly advises against echo-ing secrets and promotes short-lived credentials via OIDC, significantly reducing the risk of data exposure compared to traditional static keys.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 09:37 PM
Security Audit — agent-trust-hub — github-actions