github-actions-author
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill queries release metadata from official GitHub repositories (actions/checkout, actions/setup-node, oven-sh/setup-bun) using the GitHub CLI. These are well-known services and trusted organizations, posing no risk.
- [COMMAND_EXECUTION]: Uses standard git and gh CLI commands to manage repository state and workflow metadata as part of its primary function.
- [PROMPT_INJECTION]: No malicious instruction overrides detected. The prompt contains legitimate safety guidelines for the agent to follow (e.g., pinning permissions, avoiding hardcoded secrets).
- [CREDENTIALS_UNSAFE]: No hardcoded credentials found. The skill explicitly instructs the agent to avoid printing secrets or tokens.
Audit Metadata