github-actions

Pass

Audited by Gen Agent Trust Hub on Mar 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is an educational resource for GitHub Actions security. It does not contain any malicious code, obfuscated instructions, or unauthorized data access patterns. All external references are to official and well-known GitHub Actions.
  • [COMMAND_EXECUTION]: The skill uses rg (ripgrep) to search its internal reference documentation. This command execution is localized to the skill's files and serves as a benign mechanism for documentation retrieval.
  • [PROMPT_INJECTION]: The workflow and instructions are dedicated to CI/CD security advice. No attempts to hijack the model's behavior or bypass safety protocols were detected.
  • [DATA_EXFILTRATION]: There are no patterns of unauthorized data collection or transmission. The skill explicitly guides users on how to securely handle secrets and identities via OIDC.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 19, 2026, 11:54 AM
Security Audit — agent-trust-hub — github-actions