github-actions-creator
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements strong security defaults by requiring the
permissionsblock in all generated workflows to restrict access to theGITHUB_TOKEN(e.g.,contents: read). - [EXTERNAL_DOWNLOADS]: References official and well-known GitHub Actions from trusted organizations and services, including GitHub (actions/*), Docker, AWS, Google Cloud, Vercel, and Cloudflare. These references are documented for functionality and follow established industry standards.
- [PROMPT_INJECTION]: Includes specific instructions and code examples to mitigate script injection vulnerabilities. It explicitly warns against direct interpolation of untrusted event data (e.g.,
${{ github.event.issue.title }}) into shell commands, recommending the use of environment variables instead. - [DATA_EXFILTRATION]: No patterns of unauthorized data access or external transmission were detected. The skill focuses on standard CI/CD operations using repository-defined secrets for authentication with well-known providers.
Audit Metadata