Workflow Automation
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides instructional templates for CI/CD workflows using GitHub Actions and Harness. No malicious instructions or hidden behaviors were detected.
- [SAFE]: The skill demonstrates correct usage of secret management via platform variables (e.g., GITHUB_TOKEN, SNYK_TOKEN, AZURE_CREDENTIALS) rather than hardcoding sensitive information. Database credentials used in the integration testing examples are dummy values for local service containers, which is a standard and safe development practice.
- [SAFE]: The automation scripts and YAML configurations utilize well-known GitHub Actions from trusted or established vendors (e.g., actions/, azure/, docker/, snyk/, aquasecurity/*).
- [SAFE]: The skill actively encourages security best practices by including steps for vulnerability scanning (npm audit, Snyk, Trivy) and automated dependency updates as part of the recommended workflows.
Audit Metadata