maintainx-ci-integration

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of data from the MaintainX API. If the agent processes content from this API that is controllable by external users, it creates a surface for indirect prompt injection. This is a common characteristic of skills that interact with external data sources.
  • [EXTERNAL_DOWNLOADS]: The skill references official and widely-used GitHub Actions (e.g., actions/checkout, actions/setup-node) and CI services like Codecov. These are well-known and trusted resources in development workflows.
  • [SAFE]: The implementation examples demonstrate secure practices by using CI/CD secrets for API keys and including steps for secret detection (gitleaks) and dependency auditing (npm audit).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 03:45 AM
Security Audit — agent-trust-hub — maintainx-ci-integration