github-actions-oidc

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill acts as a security configuration assistant, emphasizing the transition from long-lived service account keys to temporary OIDC-based credentials. It provides correct and helpful security warnings regarding the use of wildcards in IAM trust policies, advising users to restrict access to specific GitHub branches or environments to prevent unauthorized access from forks or unrelated pull requests.
  • [SAFE]: The instructions for GitHub Actions YAML configuration correctly mandate the inclusion of both id-token: write and contents: read permissions, which is a common source of error that can lead to broken workflows or insecure defaults if handled incorrectly.
  • [EXTERNAL_DOWNLOADS]: The skill references several official GitHub Actions and CLI tools from trusted organizations, including Google, AWS, and Microsoft. It also utilizes the firebase-tools package via npx. These are documented neutrally and used for their intended setup and deployment purposes.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 07:56 AM
Security Audit — agent-trust-hub — github-actions-oidc