ts-ci-github-actions
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides standard configuration for GitHub Actions. It correctly identifies security and stability best practices, such as using
--frozen-lockfilefor dependency installation to prevent unauthorized or accidental lockfile changes during CI runs. - [EXTERNAL_DOWNLOADS]: The workflow templates utilize
actions/checkout@v4,actions/setup-node@v4, andpnpm/action-setup@v4. These are official GitHub actions or provided by the official pnpm organization, which are well-known and trusted services. - [CREDENTIALS_UNSAFE]: The skill mentions the use of
TURBO_TOKEN. It provides explicit instructions to store this value as a repository secret within GitHub's native secrets management system, which is the industry-standard secure practice for handling CI/CD credentials. No hardcoded credentials or secrets are present in the skill content.
Audit Metadata