agentic-actions-auditor
Pass
Audited by Gen Agent Trust Hub on Jun 21, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides detailed static analysis instructions for identifying prompt injection and misconfiguration risks in CI/CD pipelines.
- [SAFE]: It contains explicit 'Bash Safety Rules' that forbid the execution of untrusted YAML content fetched from remote repositories, mitigating remote code execution risks during the audit process.
- [SAFE]: The use of the GitHub CLI (
gh api) is appropriate for the stated purpose of retrieving workflow configurations for analysis. - [SAFE]: The skill originates from a reputable security research source (Trail of Bits) and is maintained by a known security entity.
Audit Metadata