ci-cd-pipeline

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is purely educational and defensive. It provides guidance on least privilege, secret management, and supply chain security for CI/CD environments. No malicious patterns, obfuscation, or unauthorized data access were detected. The persona is strictly focused on professional DevOps practices.
  • [EXTERNAL_DOWNLOADS]: The skill references several standard GitHub Actions and tools including actions/checkout, aws-actions/configure-aws-credentials, docker/setup-buildx-action, and tj-actions/changed-files. These are well-known, industry-standard utilities used for legitimate pipeline operations. The skill explicitly emphasizes pinning these dependencies to specific versions or SHA digests for security.
  • [INDIRECT_PROMPT_INJECTION]: While the skill ingests user queries about CI/CD pipelines (Ingestion Point: user request in SKILL.md), it does not execute code based on these inputs. Instead, it generates static workflow configuration files and provides diagnostic advice based on the provided reference files (references/patterns.md, references/sharp_edges.md, references/validations.md). All generated content is intended for user review.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 11:04 AM
Security Audit — agent-trust-hub — ci-cd-pipeline