ci-scaffolding
Pass
Audited by Gen Agent Trust Hub on Apr 30, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill generates standard GitHub Actions workflows and Git hooks from internal templates.
- [SAFE]: References to external GitHub Actions target official repositories from organizations like GitHub (actions/checkout), Astral (setup-uv), and Oven (setup-bun).
- [SAFE]: The reference material explicitly guides users on security hardening, including secret management and permission minimization.
- [SAFE]: Project detection logic reads manifest files (e.g., package.json) to determine the tech stack, which is a benign use of project metadata.
Audit Metadata