github-actions-setup

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill generates GitHub Action workflows by ingesting metadata from project files, creating a potential surface for indirect prompt injection where malicious content in those files could influence the generated configuration.
  • Ingestion points: The skill reads package.json, .nvmrc, .node-version, and playwright.config.* files to detect environment settings like package managers, Node.js versions, and test directories.
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat the data from these project files as untrusted content.
  • Capability inventory: The skill has the capability to write a new GitHub Action workflow file (.github/workflows/stably-e2e.yml) and suggest the installation of the stably package.
  • Sanitization: The skill does not describe explicit validation or sanitization of the strings detected from project files before they are interpolated into the workflow YAML templates.
  • [COMMAND_EXECUTION]: The skill generates and instructs the agent to run commands involving the stably CLI and standard package managers.
  • The instructions include checking for the stably CLI in devDependencies and offering to install it using npm install -D stably (or equivalent).
  • The generated workflow templates execute commands such as npx stably install --with-deps chromium, npx stably test, and npx stably fix.
  • These commands are for the vendor's official toolset and are standard for the stated purpose of the skill.
  • [PRIVILEGE_ESCALATION]: The "Self-healing" feature in the generated workflow requests elevated permissions for the GitHub Actions runner.
  • The workflow template includes a permissions block with contents: write and pull-requests: write.
  • This configuration is explicitly required to allow the runner to push code and create automated pull requests via the GITHUB_TOKEN to fix failing tests.
  • [EXTERNAL_DOWNLOADS]: The skill references and utilizes external resources from the vendor and well-known services.
  • It utilizes official GitHub Actions including actions/checkout@v4, actions/setup-node@v4, and actions/upload-artifact@v4.
  • It suggests installing the stably package, which is an official tool from the skill's authoring organization.
  • It directs users to https://auth.stably.ai/org/api_keys/ to retrieve their credentials, which matches the vendor's infrastructure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 12:09 AM
Security Audit — agent-trust-hub — github-actions-setup