github-actions
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides educational content and command templates for GitHub Actions development and debugging.
- [SAFE]: It explicitly promotes security best practices, such as masking secrets, setting least-privilege permissions, and pinning action versions to specific SHAs.
- [SAFE]: External references to the GitHub CLI (
gh) and the local execution toolact(nektos/act) are standard industry utilities for the intended use case. - [SAFE]: The documentation includes specific warnings against dangerous configurations, such as the potential for Remote Code Execution (RCE) when using
pull_request_targetimproperly.
Audit Metadata