×
Third-party audit

Gen Agent Trust Hub

gha-security-review · getsentry/skills

High risk
Provider summary

This skill is a security auditing tool designed to help AI agents review GitHub Actions workflows for vulnerabilities like expression injection and pwn requests. It contains detailed documentation of historical attack patterns and malicious indicators, including references to blacklisted domains used in the HackerBot Claw campaign. These references are provided strictly for educational and defensive purposes by a trusted organization, and the skill does not exhibit malicious behavior itself.

The provider classified the analyzed snapshot as CRITICAL risk. This result applies to the content available at audit time.

Provider
Gen Agent Trust Hub
Normalized result
fail
Risk level
CRITICAL
Audited
Mar 20, 2026
Interpretation

How to use this signal

01

Confirm the source

Compare the repository, publisher, and installation command before continuing.

02

Read the content

Review SKILL.md, scripts, and allowed tools. Artificial Atlas never executes them during indexing.

03

Limit permissions

Use the narrowest possible scope and avoid broad credentials for third-party skills.