finops-waste
Pass
Audited by Gen Agent Trust Hub on May 11, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
bashand the GitHub CLI (gh) to analyze repository metadata and workflow run history. These commands are restricted to the skill's stated purpose of FinOps analysis. - [SAFE]: Employs dynamic context injection (
!command) to retrieve the repository's origin URL and locate workflow files. These are benign initialization steps used to populate the agent's context with relevant project information. - [SAFE]: Analysis of remote data is conducted through the official GitHub API via a local script. No evidence of credential harvesting, unauthorized network communication, or obfuscation was detected.
Audit Metadata