audit-github-actions
Pass
Audited by Gen Agent Trust Hub on May 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves a legitimate security purpose, providing a framework for auditing CI/CD configurations against known real-world attack vectors.
- [EXTERNAL_DOWNLOADS]: The skill identifies and utilizes well-known security tools (zizmor, actionlint, pinact) from trusted sources. It explicitly advises the user on how to install these tools securely.
- [COMMAND_EXECUTION]: The skill employs standard Git and Curl commands to clone repositories and perform non-invasive probes of GitHub namespaces as part of its auditing logic.
- [DATA_EXFILTRATION]: No suspicious network activity or exfiltration patterns were detected. All network operations are aligned with the skill's auditing and verification functions.
- [PROMPT_INJECTION]: The instructions are focused on the auditing task and do not contain any patterns intended to manipulate the agent's safety filters or core programming.
Audit Metadata