actions-automation

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as an educational guide for GitHub Actions, covering triggers, reusable workflows, and automation patterns.
  • [SAFE]: It explicitly highlights security best practices, such as warning against interpolating untrusted input (client_payload) into shell blocks and recommending the two-workflow pattern for secure fork PR handling.
  • [SAFE]: All code snippets are standard YAML configurations or script examples for GitHub Actions and do not contain any malicious instructions, exfiltration patterns, or obfuscated content.
  • [SAFE]: Mentions of tools like actions/github-script and gh api are presented in a legitimate development context without any attempt to bypass security controls or execute unauthorized commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 10:14 AM
Security Audit — agent-trust-hub — actions-automation