gh-workflow
Pass
Audited by Gen Agent Trust Hub on Mar 30, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute local commands including
gitandghto manage the repository and trigger workflows. - [DATA_EXFILTRATION]: The skill performs data transfer by pushing local commits to GitHub remotes. This is consistent with the primary purpose of triggering GitHub Actions.
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to download build artifacts from GitHub via the
gh run downloadcommand.
Audit Metadata