clari-ci-integration

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides documentation and workflow templates for GitHub Actions. It does not contain any executable code that runs automatically in the agent's environment.
  • [SAFE]: Secret management instructions correctly utilize GitHub Secrets (${{ secrets.CLARI_API_KEY }}) and environment variables, avoiding the use of hardcoded credentials.
  • [SAFE]: The skill explicitly recommends security controls for CI environments, such as masked secrets, protected environment gates, and log redaction policies.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow that processes external repository data (fixtures and logs). While this is a standard vulnerability surface for CI/CD tools, the skill mitigates risk by specifying data masking and environment isolation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 01:17 PM
Security Audit — agent-trust-hub — clari-ci-integration