ci-cd-security
Pass
Audited by Gen Agent Trust Hub on Jun 12, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is an analytical tool designed to guide the model through a nine-pass security review of GitHub Actions YAML files. It relies solely on the model's internal reasoning rather than external execution.
- [SAFE]: No malicious patterns, such as prompt injection, data exfiltration, or obfuscation, were detected in the instructions or reference materials.
- [SAFE]: The skill explicitly defines a "no-tool" approach, stating it will not install or execute third-party auditing software, which minimizes the attack surface.
- [SAFE]: All external URL references are to well-known technology services (GitHub) and are used for documentation or as examples of safe/unsafe patterns.
Audit Metadata