github-actions-setup
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill generates GitHub Action workflows by ingesting metadata from project files, creating a potential surface for indirect prompt injection where malicious content in those files could influence the generated configuration.
- Ingestion points: The skill reads
package.json,.nvmrc,.node-version, andplaywright.config.*files to detect environment settings like package managers, Node.js versions, and test directories. - Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat the data from these project files as untrusted content.
- Capability inventory: The skill has the capability to write a new GitHub Action workflow file (
.github/workflows/stably-e2e.yml) and suggest the installation of thestablypackage. - Sanitization: The skill does not describe explicit validation or sanitization of the strings detected from project files before they are interpolated into the workflow YAML templates.
- [COMMAND_EXECUTION]: The skill generates and instructs the agent to run commands involving the
stablyCLI and standard package managers. - The instructions include checking for the
stablyCLI indevDependenciesand offering to install it usingnpm install -D stably(or equivalent). - The generated workflow templates execute commands such as
npx stably install --with-deps chromium,npx stably test, andnpx stably fix. - These commands are for the vendor's official toolset and are standard for the stated purpose of the skill.
- [PRIVILEGE_ESCALATION]: The "Self-healing" feature in the generated workflow requests elevated permissions for the GitHub Actions runner.
- The workflow template includes a
permissionsblock withcontents: writeandpull-requests: write. - This configuration is explicitly required to allow the runner to push code and create automated pull requests via the
GITHUB_TOKENto fix failing tests. - [EXTERNAL_DOWNLOADS]: The skill references and utilizes external resources from the vendor and well-known services.
- It utilizes official GitHub Actions including
actions/checkout@v4,actions/setup-node@v4, andactions/upload-artifact@v4. - It suggests installing the
stablypackage, which is an official tool from the skill's authoring organization. - It directs users to
https://auth.stably.ai/org/api_keys/to retrieve their credentials, which matches the vendor's infrastructure.
Audit Metadata