github-actions
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides educational content and technical references for GitHub Actions workflow development.
- [SAFE]: Code examples demonstrate security best practices, including the use of OIDC for cloud authentication and the implementation of the Principle of Least Privilege via workflow-level and job-level permissions.
- [SAFE]: The documentation includes explicit warnings and remediation strategies for common security vulnerabilities, such as script injection in
run:blocks and the risks associated with thepull_request_targettrigger. - [SAFE]: External actions and tools referenced (e.g., official GitHub actions, Docker, AWS, Google Cloud, and Azure integrations) are from well-known and reputable organizations.
Audit Metadata