github-actions-author

Pass

Audited by Gen Agent Trust Hub on May 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is composed entirely of static Markdown documentation and YAML templates. It contains no executable scripts, binaries, or automated tasks that could compromise the host environment.- [SAFE]: External references to GitHub Actions in the templates point to official, well-known repositories (e.g., actions/checkout, actions/setup-node) and correctly implement SHA-pinning for supply chain security.- [PROMPT_INJECTION]: The 'review' mode ingests and analyzes user-provided YAML files (SKILL.md). While this serves as an ingestion point for untrusted data without explicit boundary markers or sanitization, the risk is negligible as the skill's capability inventory is limited to textual reporting and it lacks access to dangerous tools like shell execution or network requests.
Audit Metadata
Risk Level
SAFE
Analyzed
May 17, 2026, 04:53 AM
Security Audit — agent-trust-hub — github-actions-author