ci-cd-pipelines

Pass

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides comprehensive instructions for building CI/CD pipelines that adhere to security best practices, such as masking dynamic tokens with ::add-mask:: and using environment-specific secrets.
  • [EXTERNAL_DOWNLOADS]: The workflow templates reference official and well-known GitHub Actions from trusted organizations (e.g., actions/*, docker/*, pnpm/*, changesets/*). These references are standard for the intended DevOps use-case.
  • [COMMAND_EXECUTION]: The skill includes shell command examples for common tools like kubectl, az, docker, and various package managers (pnpm, pip, go). These are used correctly within the context of deployment and build automation documentation.
  • [SAFE]: No obfuscation, prompt injection, or data exfiltration patterns were found in the instructions or provided templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 26, 2026, 09:13 PM
Security Audit — agent-trust-hub — ci-cd-pipelines