ci-cd-pipeline-builder

Pass

Audited by Gen Agent Trust Hub on Jun 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues were detected. The skill performs standard engineering automation using Python scripts that rely on the standard library for local file operations.
  • [COMMAND_EXECUTION]: The skill executes local Python scripts (stack_detector.py and pipeline_generator.py) to analyze repositories and generate configuration files. These scripts do not use dangerous functions such as os.system or eval, nor do they invoke shell commands with user-supplied arguments.
  • [DATA_EXFILTRATION]: No network operations (e.g., curl, wget, requests) or attempts to access sensitive system paths (e.g., ~/.ssh, ~/.aws, .env) were identified. The skill operates exclusively on local project metadata.
  • [PROMPT_INJECTION]: The skill instructions and documentation are focused on DevOps automation and do not contain patterns designed to override agent safety guidelines or behavior.
  • [CREDENTIALS_UNSAFE]: No hardcoded secrets, tokens, or private keys were found. The skill explicitly advises users to document required secrets rather than embedding them in the generated CI/CD YAML files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 21, 2026, 06:42 PM
Security Audit — agent-trust-hub — ci-cd-pipeline-builder