dev-ci
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFE
Full Analysis
- GitHub CLI Integration: The skill provides a structured procedure for using the GitHub CLI (
gh) to monitor, triage, and download artifacts from CI runs. This involves standard administrative tasks within a developer's environment. - Operational Protocols: The instructions define strict process rules for the agent, such as requiring a written diagnosis before rerunning a job (e.g., 'stop the line'). These directives are designed to enforce best practices for CI/CD reliability rather than bypassing security guardrails.
- Workflow Security Best Practices: The skill promotes security-conscious behavior by recommending the pinning of external GitHub Actions to specific commit SHAs and using contract tests to verify that CI configurations do not include unsafe patterns like
continue-on-error. - Log Ingestion Surface: The agent is instructed to analyze CI logs and job metadata. While this involves processing external build data, it is a core function of the skill and uses standard filtering tools like
jqandgrepto identify common failure patterns.
Audit Metadata