scanning-containers-with-trivy-in-cicd
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides legitimate educational content for container security scanning using industry-standard tools and practices.
- [EXTERNAL_DOWNLOADS]: References the official
aquasecurity/trivy-actionand standard GitHub Actions (actions/checkout,actions/cache,github/codeql-action). These are well-known services and are used according to their intended security purpose. - [COMMAND_EXECUTION]: Includes standard CLI commands for Docker and Trivy. All shell operations are transparent, relevant to the stated purpose, and do not involve suspicious execution patterns or privilege escalation.
Audit Metadata