depot-github-actions

Pass

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements defensive instruction sets designed to prevent common CI/CD security pitfalls. It specifically mandates that migrations must be plan-only if evidence is missing or if topology is unresolved.
  • [SAFE]: Security best practices for GitHub Actions are enforced, such as identifying pull_request_target as a privileged execution environment and blocking the addition of sensitive credentials (secrets, registry authority) to jobs that process untrusted external code.
  • [SAFE]: The skill utilizes a transactional editing model which includes capturing hashes of target files and performing drift checks immediately before mutation to ensure atomicity and prevent accidental overwrites of concurrent changes.
  • [SAFE]: Analysis is restricted to read-only operations using Read, Glob, and Grep tools. There are no patterns of remote code execution, package installation, or external network requests within the skill's instructions or logic.
  • [SAFE]: Guidance on cache management explicitly warns against placing secrets in cache keys or paths and advises on preventing cache poisoning by low-trust jobs.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 3, 2026, 01:05 AM
Security Audit — agent-trust-hub — depot-github-actions