python-ci
Pass
Audited by Gen Agent Trust Hub on Jul 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides instructions and bundled resources dedicated to implementing security best practices for CI/CD, including guidance on mitigating supply-chain risks and hardening workflow permissions.
- [EXTERNAL_DOWNLOADS]: Fetches and utilizes recognized security and development tools, such as the
zizmorscanner,actionlint, and official GitHub Actions (actions/checkout,astral-sh/setup-uv), from trusted organizations and well-known services. - [COMMAND_EXECUTION]: Includes a bundled hygiene scanner (
scripts/check_workflows.py) that performs read-only analysis of local workflow configuration files to identify security misconfigurations without modifying the environment.
Audit Metadata