devsecops-pipeline

Pass

Audited by Gen Agent Trust Hub on May 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a template generator for standard security practices and does not perform runtime code execution or sensitive data access.
  • [EXTERNAL_DOWNLOADS]: The generated workflows reference reputable GitHub Actions from well-known organizations including GitHub, Semgrep, and Aqua Security. These are standard components for secure development pipelines.
  • [PROMPT_INJECTION]: No attempts to bypass safety filters or override system instructions were found in the skill metadata or body.
  • [DATA_EXFILTRATION]: The skill does not access local sensitive files or environment variables and lacks any unauthorized data transmission patterns.
  • [REMOTE_CODE_EXECUTION]: All referenced tools are standard CI/CD actions and the skill itself does not involve executing unverified remote scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
May 17, 2026, 12:39 PM
Security Audit — agent-trust-hub — devsecops-pipeline