All skills
bitwarden avatar

/action-remediate

@f959329 official
by bitwardenbitwarden/ai-plugins155 stars
20

Remediate GitHub Actions action findings identified by the action-audit skill. Applies the appropriate fix per action type β€” `@main` ref for internal `bitwarden/` actions, full SHA with inline version comment for external actions, or full replacement β€” across selected repos and creates draft PRs. Run the action-audit skill first to identify findings before using this skill. <example> User: Go ahead and fix the unpinned actions from the audit Action: Trigger action-remediate to apply fixes and create PRs </example> <example> User: Replace tj-actions/changed-files with the safe version across those repos Action: Trigger action-remediate to swap the action and create PRs </example>

Use this Skill: https://skilld.dev/gh/bitwarden/ai-plugins/action-remediate

This session only. Nothing lands on disk.

SKILL.md

β‰ˆ177 tokens always: the name and description. β‰ˆ857 when used: this file.

Rules

  • No mutating API calls without confirmation. gh api GET requests are allowed freely. Any call using -X POST, -X PUT, -X PATCH, or -X DELETE must be shown to the user and approved before execution.
  • Never force-push, delete branches, or delete repositories.
  • Only modify files under .github/. Do not touch application code, scripts, or configuration outside of workflow files.
  • Show a diff and get confirmation before handing off for commit.
  • All PRs must be created as drafts.
  • Flag uncertainty. If a finding is ambiguous or a fix could break a workflow, stop and ask rather than guessing.

Step 1: Confirm Audit Findings

Before proceeding, verify that the user has audit findings to act on. These should come from a prior run of the action-audit skill. Confirm:

  • Which repos to remediate (all, a subset, or specific ones)
  • The remediation approach:
    • pin to main β€” for internal bitwarden/ actions: change the ref to @main
    • pin update β€” for external actions: update to a verified 40-character SHA with an inline version comment
    • replace β€” swap to a different action entirely
  • The target SHA, replacement action, or confirmation that @main is the fix

If any of this is unclear, ask the user before continuing.

Step 2: Apply Fixes Per Repo

For each selected repo:

  1. Ask the user for the base directory where their repos are cloned (if not already known). Check if a local clone exists at <base-dir>/<repo>. If not, inform the user and skip that repo.

  2. Create a fix branch:

    git checkout -b fix/action-remediation-<action-name-slug>
  3. Apply the fix to each affected file based on the remediation approach:

    • Pin to main (internal bitwarden/ actions): Replace the ref with @main β€” e.g., uses: bitwarden/gh-actions/action@v1 β†’ uses: bitwarden/gh-actions/action@main. No SHA resolution needed.
    • Pin update (external actions): Replace the uses: line with uses: <action>@<sha> # <original-ref>
    • Replace: Before applying, verify the replacement action is on Bitwarden's approved actions list in bitwarden/workflow-linter. Then swap uses: <old-action>@<ref> with uses: <new-action>@<sha> # <tag>
  4. Show a git diff of changes in this repo and get confirmation before proceeding.

Step 3: Commit, Push, and Create PRs

Do not run the staging, commit, or push commands yourself. For each repo, present the block below for the user to run manually as a suggestion:

git add .github/
git commit -m "Remediate <action-name> action usage"
git push -u origin fix/action-remediation-<action-name-slug>

Once the user confirms the push, create the draft PR:

gh pr create \
  --title "Remediate <action-name> action usage" \
  --body "$(cat <<'EOF'
## Summary

Remediates usage of `<action-name>` across this repository.

**Action taken:** <pin updated to `<sha>` / replaced with `<new-action>`>

**Reason:** <compromised action / deprecated action / unpinned reference>
EOF
)" \
  --draft

Step 4: Final Summary

Output a summary of all actions taken:

Repo Files Changed PR Created Notes
... ... ... ...

Remind the user that code search results may have a lag and to verify no repos were missed by checking manually if this is a security incident.

Source: SKILL.md on GitHub

No alerts14d3 checks Β· Risk SAFE
  • Gen Agent Trust Hub14d

    The skill is designed to remediate GitHub Actions security findings by pinning actions to specific versions or SHAs. It follows security best practices by requiring user confirmation for all mutations, providing diffs for review, and limiting changes to the .github/ directory. All identified behaviors are consistent with its stated purpose as a security tool.

  • Socket14d

    No alerts

  • Snyk14d

    Risk: LOW Β· No issues

Signed by skilld at f959329. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 3 months ago
What it can do
Reads files Edits files Runs commands
All 7 allowed tools
ReadEditGlobGrepBash(gh pr create:*)Bash(git checkout:*)Bash(git diff:*)
  • Security
  • github-actions
  • remediation
  • bitwarden
  • workflow
  • pinning
  • draft-pr

README badge

README badge for bitwarden/ai-plugins/action-remediate

Applies fixes to GitHub Actions findings from the action-audit skill, updating unpinned or compromised actions to either `@main` (internal Bitwarden actions), full SHA with version comment (external actions), or a replacement action, then creates draft PRs. Depends on action-audit output and requires local repo clones and GitHub CLI access.

Generated from the current SKILL.md.

What does this skill do?
This skill applies fixes to GitHub Actions findings identified by the action-audit skill. It pins internal Bitwarden actions to @main, pins external actions to verified SHAs with inline version comments, or replaces actions entirely, then creates draft PRs across selected repos.
Do I need to run action-audit first?
Yes. This skill remediates findings from action-audit. Run action-audit to identify unpinned or unsafe actions before using this skill.
Will this create pull requests automatically?
No. The skill shows a diff for each repo and requires your confirmation before committing and creating draft PRs.
What files does this modify?
Only files under `.github/` β€” workflow files. Application code, scripts, and configuration outside workflows are never touched.
Does this work with local repos only?
Yes. The skill requires local clones of your repos. It checks if each repo exists at the base directory you provide and skips any that are not found locally.

Generated from the current SKILL.md. These answers refresh after source changes.