depot-github-actions
Pass
Audited by Gen Agent Trust Hub on Aug 3, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements defensive instruction sets designed to prevent common CI/CD security pitfalls. It specifically mandates that migrations must be plan-only if evidence is missing or if topology is unresolved.
- [SAFE]: Security best practices for GitHub Actions are enforced, such as identifying
pull_request_targetas a privileged execution environment and blocking the addition of sensitive credentials (secrets, registry authority) to jobs that process untrusted external code. - [SAFE]: The skill utilizes a transactional editing model which includes capturing hashes of target files and performing drift checks immediately before mutation to ensure atomicity and prevent accidental overwrites of concurrent changes.
- [SAFE]: Analysis is restricted to read-only operations using
Read,Glob, andGreptools. There are no patterns of remote code execution, package installation, or external network requests within the skill's instructions or logic. - [SAFE]: Guidance on cache management explicitly warns against placing secrets in cache keys or paths and advises on preventing cache poisoning by low-trust jobs.
Audit Metadata