gha-security-review
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides benign instructional content for security analysis tasks and does not contain any executable code or unauthorized commands.\n- [INDIRECT_PROMPT_INJECTION]: The skill is intended to process untrusted files from external repositories, which presents an inherent surface for indirect prompt injection if those files contain adversarial content.\n
- Ingestion points: Processes
.github/workflows/*.yml,action.yml,CLAUDE.md,AGENTS.md, and other repository files.\n - Boundary markers: None explicitly defined in the skill instructions.\n
- Capability inventory: The skill provides logic for analysis; tool capabilities depend on the host agent execution environment.\n
- Sanitization: The skill does not prescribe specific sanitization or filtering logic for the input repository data.
Audit Metadata