github-actions-workflows
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists of documentation and YAML configuration examples for GitHub Actions; it does not contain any scripts, executables, or obfuscated code.
- [SAFE]: The patterns provided for secret handling, such as using environment secrets and OIDC for cloud provider authentication, follow security best practices to prevent credential exposure.
- [SAFE]: All external actions referenced in the templates are from well-known and reputable organizations (e.g., GitHub, AWS, Docker, Slack).
- [SAFE]: The guidance explicitly recommends security hardening techniques, including pinning actions to specific commit SHAs and defining granular workflow permissions.
Audit Metadata