skills/nvidia/nemo-fabric/maintain-ci/Gen Agent Trust Hub

maintain-ci

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill functions as a defensive guidance document for CI/CD maintenance, promoting the principle of least privilege by recommending job-level permissions.
  • [SAFE]: It encourages supply chain security by instructing users to pin third-party actions to full commit SHAs and maintain deterministic environments via lockfiles.
  • [COMMAND_EXECUTION]: Suggests the use of local utility commands such as just and ripgrep for validating and inspecting workflow files, which are standard practices for development work and do not involve remote or malicious execution.
  • [EXTERNAL_DOWNLOADS]: Mentions well-known ecosystem tools and GitHub Actions like setup-uv and rust-cache for performance and reliability, following standard integration patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 03:00 AM
Security Audit — agent-trust-hub — maintain-ci