woodpecker-ci

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues were detected. The skill provides templates and instructions for Woodpecker CI that adhere to standard security practices.
  • [SAFE]: The included diagnostic script (scripts/woodpecker-doctor.py) uses only standard Python libraries and performs connectivity checks without exfiltrating sensitive data. It safely checks for the presence of secrets using boolean logic rather than accessing or printing the values.
  • [SAFE]: The documentation explicitly warns users about the security implications of mounting the Docker socket and provides recommendations for using Kubernetes namespaces and RBAC for isolating untrusted workloads.
  • [SAFE]: Templates use environment variable placeholders for secrets, discouraging hardcoding, and instructions include guidance on generating high-entropy secrets using standard tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 05:57 PM
Security Audit — agent-trust-hub — woodpecker-ci