build-yaml-misconfiguration
Pass
Audited by Gen Agent Trust Hub on Jul 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists of instructional markdown content designed to guide an AI agent in identifying and preventing security misconfigurations in CI/CD pipelines.
- [SAFE]: Security guidelines regarding secret management (vaults, protected variables, masking), isolation (runners, non-root users), and permissions follow industry best practices.
- [SAFE]: All instances of insecure code (e.g., hardcoded secrets or privileged execution) are explicitly labeled as 'BAD' and are intended for detection purposes, not execution.
- [SAFE]: External references point to well-known open-source initiatives (CoSAI Project CodeGuard) or are used as standard placeholders in examples.
- [SAFE]: No obfuscation, data exfiltration, or unauthorized command execution patterns were found.
Audit Metadata