finops-waste

Pass

Audited by Gen Agent Trust Hub on May 11, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses bash and the GitHub CLI (gh) to analyze repository metadata and workflow run history. These commands are restricted to the skill's stated purpose of FinOps analysis.
  • [SAFE]: Employs dynamic context injection (!command) to retrieve the repository's origin URL and locate workflow files. These are benign initialization steps used to populate the agent's context with relevant project information.
  • [SAFE]: Analysis of remote data is conducted through the official GitHub API via a local script. No evidence of credential harvesting, unauthorized network communication, or obfuscation was detected.
Audit Metadata
Risk Level
SAFE
Analyzed
May 11, 2026, 07:25 PM
Security Audit — agent-trust-hub — finops-waste