codeql

Pass

Audited by Gen Agent Trust Hub on Apr 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill facilitates the setup of CodeQL for security scanning using official and well-known GitHub Actions (e.g., github/codeql-action/init, github/codeql-action/analyze). These sources are from a trusted organization and do not pose a security risk.
  • [SAFE]: Environment discovery commands, such as using rg to scan workflows and checking for the codeql binary, are standard practices for determining the current state of a repository's CI configuration.
  • [SAFE]: Documentation and code examples provided for C# security queries (e.g., SQL injection, XSS) are educational and align with industry-standard security analysis practices.
  • [SAFE]: No instances of obfuscation, credential exfiltration, or unauthorized network operations were detected. All external links point to official GitHub and CodeQL documentation domains.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 22, 2026, 02:18 AM