github-actions-advanced

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill acts as a security-focused educational resource, teaching users how to harden CI/CD pipelines and providing robust, safe-by-design examples.
  • [SAFE]: Implements the Principle of Least Privilege by demonstrating the use of the permissions block to restrict GITHUB_TOKEN scopes at both the workflow and job levels.
  • [SAFE]: Advocates for supply chain security by recommending that third-party actions be pinned to a full 40-character commit SHA, ensuring the integrity of external code.
  • [SAFE]: Provides specific guidance on preventing shell injection vulnerabilities by passing untrusted metadata (like pull request titles) through environment variables rather than direct interpolation in shell scripts.
  • [SAFE]: Recommends the use of OpenID Connect (OIDC) for keyless authentication with cloud providers, eliminating the security risks associated with long-lived credentials.
  • [SAFE]: All external actions and tools mentioned in the documentation are sourced from trusted vendors and well-known technology organizations.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 12:14 PM
Security Audit — agent-trust-hub — github-actions-advanced