github-supply-chain-hardening-analysis

Pass

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses Python's subprocess.run with shell=False to invoke the git and gh CLI tools. These operations are strictly controlled, targeting only the necessary commands to clone repositories and retrieve authentication metadata as part of the tool's core auditing functionality.
  • [CREDENTIALS_UNSAFE]: The skill accesses GitHub tokens from environment variables and CLI state (gh auth token). It implements a dedicated _sanitize_message function to ensure that these tokens are redacted from all command output, error messages, and written files, preventing accidental exposure.
  • [EXTERNAL_DOWNLOADS]: The skill communicates with the official GitHub API (api.github.com) to enumerate repositories. This communication is restricted to the established GitHub domain and uses the user's own discovered credentials to perform read-only metadata lookups.
  • [DATA_EXFILTRATION]: Repository analysis is performed on local clones stored in temporary directories. No sensitive repository content or the generated security proposals are sent to external third-party servers; all results are stored in a user-defined local output directory.
  • [SAFE]: The skill includes deterministic static analysis heuristics to detect hardcoded secrets and insecure CI/CD patterns (such as unpinned GitHub Actions). These findings are reported in a structured JSON format and specifically redact secret values, prioritizing user security.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 25, 2026, 07:34 PM
Security Audit — agent-trust-hub — github-supply-chain-hardening-analysis