actions-authoring
Pass
Audited by Gen Agent Trust Hub on Aug 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists entirely of educational content and code snippets that demonstrate secure vs. insecure patterns in GitHub Actions. No executable code or autonomous actions are present.
- [SAFE]: It correctly identifies and explains critical security risks including unsafe use of
pull_request_target, script injection vulnerabilities via shell interpolation, and the risks of unpinned third-party actions. - [SAFE]: Recommendations align with industry standard best practices, such as applying the principle of least privilege through explicit workflow permissions and using OIDC for cloud authentication.
Audit Metadata