ts-ci-github-actions

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides standard configuration for GitHub Actions. It correctly identifies security and stability best practices, such as using --frozen-lockfile for dependency installation to prevent unauthorized or accidental lockfile changes during CI runs.
  • [EXTERNAL_DOWNLOADS]: The workflow templates utilize actions/checkout@v4, actions/setup-node@v4, and pnpm/action-setup@v4. These are official GitHub actions or provided by the official pnpm organization, which are well-known and trusted services.
  • [CREDENTIALS_UNSAFE]: The skill mentions the use of TURBO_TOKEN. It provides explicit instructions to store this value as a repository secret within GitHub's native secrets management system, which is the industry-standard secure practice for handling CI/CD credentials. No hardcoded credentials or secrets are present in the skill content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 01:06 AM
Security Audit — agent-trust-hub — ts-ci-github-actions