skills/google/capsem/dev-ci/Gen Agent Trust Hub

dev-ci

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFE
Full Analysis
  • GitHub CLI Integration: The skill provides a structured procedure for using the GitHub CLI (gh) to monitor, triage, and download artifacts from CI runs. This involves standard administrative tasks within a developer's environment.
  • Operational Protocols: The instructions define strict process rules for the agent, such as requiring a written diagnosis before rerunning a job (e.g., 'stop the line'). These directives are designed to enforce best practices for CI/CD reliability rather than bypassing security guardrails.
  • Workflow Security Best Practices: The skill promotes security-conscious behavior by recommending the pinning of external GitHub Actions to specific commit SHAs and using contract tests to verify that CI configurations do not include unsafe patterns like continue-on-error.
  • Log Ingestion Surface: The agent is instructed to analyze CI logs and job metadata. While this involves processing external build data, it is a core function of the skill and uses standard filtering tools like jq and grep to identify common failure patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 06:45 PM
Security Audit — agent-trust-hub — dev-ci