skills/petr-korobeinikov/skills/act/Gen Agent Trust Hub

act

Pass

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill demonstrates high security awareness by explicitly forbidding dangerous installation patterns, such as piping remote scripts to a shell (curl-pipe-bash). It mandates using 'mise' for package management with pinned versions.
  • [COMMAND_EXECUTION]: The skill performs necessary shell operations using act, docker, and git. These are strictly scoped to the primary purpose of smoke-testing GitHub Actions and include a 'human-in-the-loop' requirement where the tool is presented as a proposal the operator must accept.
  • [DATA_EXFILTRATION]: While the skill interacts with .secrets files, this is limited to local file access required for the 'act' tool's functionality. There are no patterns suggesting data is sent to unauthorized external domains.
  • [PROMPT_INJECTION]: The skill instructions include safety-conscious guidance for the agent, such as not guessing images and defaulting to asking the operator if environment failures are ambiguous, which reduces the risk of the agent taking unintended autonomous actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 28, 2026, 02:34 PM
Security Audit — agent-trust-hub — act