github-actions-advanced

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides comprehensive templates and guidance for GitHub Actions that strictly align with industry security standards and best practices.
  • [SAFE]: External dependencies, such as actions from the 'actions', 'docker', 'aws-actions', 'google-github-actions', and 'azure' organizations, are sourced from well-known and trusted entities.
  • [SAFE]: The instructions explicitly promote defensive configurations, including pinning third-party actions to immutable commit SHAs, declaring granular permissions to enforce the principle of least privilege, and using environment variables to mitigate shell injection risks.
  • [SAFE]: Security-enhancing tools like 'step-security/harden-runner' and 'aquasecurity/trivy-action' are integrated into the provided patterns to monitor egress traffic and scan for vulnerabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 04:34 PM
Security Audit — agent-trust-hub — github-actions-advanced