github-actions-creator

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements strong security defaults by requiring the permissions block in all generated workflows to restrict access to the GITHUB_TOKEN (e.g., contents: read).
  • [EXTERNAL_DOWNLOADS]: References official and well-known GitHub Actions from trusted organizations and services, including GitHub (actions/*), Docker, AWS, Google Cloud, Vercel, and Cloudflare. These references are documented for functionality and follow established industry standards.
  • [PROMPT_INJECTION]: Includes specific instructions and code examples to mitigate script injection vulnerabilities. It explicitly warns against direct interpolation of untrusted event data (e.g., ${{ github.event.issue.title }}) into shell commands, recommending the use of environment variables instead.
  • [DATA_EXFILTRATION]: No patterns of unauthorized data access or external transmission were detected. The skill focuses on standard CI/CD operations using repository-defined secrets for authentication with well-known providers.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 12:14 PM
Security Audit — agent-trust-hub — github-actions-creator