github-project-automation

Pass

Audited by Gen Agent Trust Hub on Jun 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides standard templates and utility scripts for managing GitHub repository automation tasks like CI/CD, security scanning, and issue tracking.
  • [SAFE]: Workflow templates follow industry security standards by using SHA-256 pinning for GitHub Actions instead of mutable version tags, preventing supply chain attacks.
  • [SAFE]: Included bash scripts, such as the setup wizard and synchronization script, perform local file operations to organize repository structure and do not exhibit malicious behavior or unauthorized data exfiltration.
  • [SAFE]: Documentation provides clear security guidance, specifically warning against hardcoding secrets and recommending the use of encrypted repository secrets and official security tools like CodeQL and Dependabot.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 14, 2026, 09:40 AM
Security Audit — agent-trust-hub — github-project-automation