Review recommended
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
passThe skill provides comprehensive guidance and templates for setting up CI/CD pipelines using GitHub Actions. It correctly emphasizes the use of secrets managers over hardcoding credentials. A potential indirect prompt injection risk exists where the skill suggests feeding raw CI failure logs back to the agent, as these logs could contain malicious instructions from untrusted code in a Pull Request.
Socket
passNo alerts
Snyk
passRisk: LOW · No issues
Runlayer
warn1/1 file flagged
ZeroLeaks
passScore: 93/100 · 2 sections analyzed