ci-pipeline-and-gates

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The workflow template in references/workflow-skeleton.md downloads and executes several GitHub Actions. These include official GitHub-maintained actions and subosito/flutter-action, which is a recognized community tool for Flutter environments.
  • [COMMAND_EXECUTION]: The skill provides shell scripts (scripts/ci-gates.sh and scripts/banned-strings.sh) that facilitate local execution of standard Flutter development commands. These tools include dart format, flutter analyze, and flutter test, which are used to verify code quality.
  • [PRIVILEGE_ESCALATION]: The CI workflow template includes a sudo apt-get install command to provision system-level dependencies (libsqlite3-dev) required for database testing. This is standard and expected behavior for configuring ephemeral CI runners.
  • [INDIRECT_PROMPT_INJECTION]: The "banned-strings" gate scans project source files and Android manifests for specific patterns using regex-based matching. This analysis is performed statically and does not involve dynamic execution of the analyzed content or interpolation into agent instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 05:45 PM
Security Audit — agent-trust-hub — ci-pipeline-and-gates