fathom-ci-integration

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides standard and secure CI/CD configurations for GitHub Actions.\n
  • The GitHub Actions workflow correctly utilizes GitHub Secrets instead of hardcoding credentials.\n
  • Instructions explicitly mandate that pull request validations be credential-free to prevent secret leakage to forked code.\n- [SAFE]: Network requests in integration tests target the official api.fathom.video domain, which is a well-known and legitimate service.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes CI/CD pipeline data, representing a potential but well-mitigated attack surface.\n
  • Ingestion points: Repository code and pull request metadata in SKILL.md.\n
  • Boundary markers: Instructions require redaction and credential-free testing.\n
  • Capability inventory: Tools include file editing and GitHub CLI access.\n
  • Sanitization: Recommends mocking data and redacting receipts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 03:46 AM
Security Audit — agent-trust-hub — fathom-ci-integration