github-supply-chain-hardening-analysis
Pass
Audited by Gen Agent Trust Hub on Jul 25, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses Python's
subprocess.runwithshell=Falseto invoke thegitandghCLI tools. These operations are strictly controlled, targeting only the necessary commands to clone repositories and retrieve authentication metadata as part of the tool's core auditing functionality. - [CREDENTIALS_UNSAFE]: The skill accesses GitHub tokens from environment variables and CLI state (
gh auth token). It implements a dedicated_sanitize_messagefunction to ensure that these tokens are redacted from all command output, error messages, and written files, preventing accidental exposure. - [EXTERNAL_DOWNLOADS]: The skill communicates with the official GitHub API (
api.github.com) to enumerate repositories. This communication is restricted to the established GitHub domain and uses the user's own discovered credentials to perform read-only metadata lookups. - [DATA_EXFILTRATION]: Repository analysis is performed on local clones stored in temporary directories. No sensitive repository content or the generated security proposals are sent to external third-party servers; all results are stored in a user-defined local output directory.
- [SAFE]: The skill includes deterministic static analysis heuristics to detect hardcoded secrets and insecure CI/CD patterns (such as unpinned GitHub Actions). These findings are reported in a structured JSON format and specifically redact secret values, prioritizing user security.
Audit Metadata