github-actions-advanced
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill acts as a security-focused educational resource, teaching users how to harden CI/CD pipelines and providing robust, safe-by-design examples.
- [SAFE]: Implements the Principle of Least Privilege by demonstrating the use of the permissions block to restrict GITHUB_TOKEN scopes at both the workflow and job levels.
- [SAFE]: Advocates for supply chain security by recommending that third-party actions be pinned to a full 40-character commit SHA, ensuring the integrity of external code.
- [SAFE]: Provides specific guidance on preventing shell injection vulnerabilities by passing untrusted metadata (like pull request titles) through environment variables rather than direct interpolation in shell scripts.
- [SAFE]: Recommends the use of OpenID Connect (OIDC) for keyless authentication with cloud providers, eliminating the security risks associated with long-lived credentials.
- [SAFE]: All external actions and tools mentioned in the documentation are sourced from trusted vendors and well-known technology organizations.
Audit Metadata