loom-ci-cd
Pass
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides standard CI/CD documentation and templates that follow security best practices. It correctly advises on the use of secrets management systems rather than hardcoding credentials.
- [SAFE]: All external references in the provided examples point to official GitHub Actions, well-known security tools (CodeQL, SonarQube, Trivy, Snyk, TruffleHog), and established cloud providers (AWS, Azure). These are standard dependencies for CI/CD workflows.
- [SAFE]: Shell commands used in the instructions and examples are standard for the described tasks (e.g., git, npm, docker, kubectl, pip) and do not exhibit any malicious patterns like unexpected data exfiltration or privilege escalation.
Audit Metadata