agentic-actions-auditor

Pass

Audited by Gen Agent Trust Hub on May 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is purely defensive and educational. It provides comprehensive documentation on identifying common attack vectors in GitHub Actions AI integrations, such as direct expression injection and environment variable intermediaries.
  • [SAFE]: All tool usage is restricted to analytical tasks. The Bash instructions are scoped to listing and fetching repository content via the GitHub CLI (gh api), which is consistent with the tool's auditing purpose.
  • [SAFE]: The methodology includes explicit safety rules, such as prohibiting the execution of fetched YAML content and treating remote data strictly as read-only material for analysis.
  • [SAFE]: No instances of obfuscation, hidden URLs, or unauthorized data access were detected. The references to external repositories are provided as educational examples of vulnerable patterns for auditing purposes.
Audit Metadata
Risk Level
SAFE
Analyzed
May 11, 2026, 10:18 PM
Security Audit — agent-trust-hub — agentic-actions-auditor