fathom-ci-integration
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides standard and secure CI/CD configurations for GitHub Actions.\n
- The GitHub Actions workflow correctly utilizes GitHub Secrets instead of hardcoding credentials.\n
- Instructions explicitly mandate that pull request validations be credential-free to prevent secret leakage to forked code.\n- [SAFE]: Network requests in integration tests target the official
api.fathom.videodomain, which is a well-known and legitimate service.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes CI/CD pipeline data, representing a potential but well-mitigated attack surface.\n - Ingestion points: Repository code and pull request metadata in SKILL.md.\n
- Boundary markers: Instructions require redaction and credential-free testing.\n
- Capability inventory: Tools include file editing and GitHub CLI access.\n
- Sanitization: Recommends mocking data and redacting receipts.
Audit Metadata