github-actions-author

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill queries release metadata from official GitHub repositories (actions/checkout, actions/setup-node, oven-sh/setup-bun) using the GitHub CLI. These are well-known services and trusted organizations, posing no risk.
  • [COMMAND_EXECUTION]: Uses standard git and gh CLI commands to manage repository state and workflow metadata as part of its primary function.
  • [PROMPT_INJECTION]: No malicious instruction overrides detected. The prompt contains legitimate safety guidelines for the agent to follow (e.g., pinning permissions, avoiding hardcoded secrets).
  • [CREDENTIALS_UNSAFE]: No hardcoded credentials found. The skill explicitly instructs the agent to avoid printing secrets or tokens.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 06:04 PM
Security Audit — agent-trust-hub — github-actions-author