skills/uinaf/agents/gh-setup/Gen Agent Trust Hub

gh-setup

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the GitHub CLI (gh) for repository introspection, checking environments, permissions, and rulesets. It also employs standard development toolchains including npm, pnpm, cargo, goreleaser, and pod to manage releases and deployments.
  • [EXTERNAL_DOWNLOADS]: The skill references several well-known third-party GitHub Actions to perform specialized tasks. These include zizmorcore/zizmor-action for workflow security auditing, cycjimmy/semantic-release-action for automated versioning, and Justintime50/homebrew-releaser for formula updates. The documentation explicitly advises pinning these dependencies to full commit SHAs and using Dependabot for updates, which aligns with security best practices.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 07:19 AM
Security Audit — agent-trust-hub — gh-setup