cicd-expert

Fail

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPRIVILEGE_ESCALATION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides an implementation example in SKILL.md that fetches a shell script from a remote URL (https://raw.githubusercontent.com/rhysd/actionlint/main/scripts/download-actionlint.bash) and pipes it directly into the bash interpreter using process substitution (bash <(curl ...)). This pattern is a critical security anti-pattern that allows for the execution of unverified remote code, creating a significant supply chain vulnerability if the remote source or transmission is compromised.
  • [EXTERNAL_DOWNLOADS]: The skill instructions frequently recommend downloading and executing external tools and scripts, including actionlint, opa (Open Policy Agent), semgrep, snyk, and various GitHub Actions. Many of these tools are downloaded from personal or non-whitelisted third-party repositories without integrity verification.
  • [COMMAND_EXECUTION]: The skill is designed to generate and execute complex shell commands and CI/CD pipelines. These operations often involve sensitive tasks such as secret injection, artifact signing, and production infrastructure management.
  • [PRIVILEGE_ESCALATION]: The documentation in references/security-gates.md provides instructions for privileged system operations, specifically using sudo to move binaries to system-wide paths (sudo mv opa /usr/local/bin/).
Recommendations
  • HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/rhysd/actionlint/main/scripts/download-actionlint.bash - DO NOT USE without thorough review
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 14, 2026, 05:54 PM
Security Audit — agent-trust-hub — cicd-expert