github-actions-oidc-aws

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill documents a security-enhancing pattern (OIDC) that replaces high-risk static credentials with short-lived tokens, aligning with industry best practices for CI/CD security.
  • [SAFE]: All referenced GitHub Actions (e.g., aws-actions/configure-aws-credentials, actions/checkout) and domains (e.g., token.actions.githubusercontent.com) are from official and trusted sources.
  • [SAFE]: The provided IAM trust policies and permission examples explicitly recommend and demonstrate how to scope access to specific repositories, branches, and environments, upholding the principle of least privilege.
  • [SAFE]: Troubleshooting and diagnostic commands provided for AWS CLI, GitHub CLI, and Shell are designed for local auditing and do not involve unauthorized data exfiltration, obfuscation, or remote code execution from untrusted sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 01:36 PM
Security Audit — agent-trust-hub — github-actions-oidc-aws