All skills
github avatar

/github-actions-hardening

@0bd4166 official
by githubgithub/awesome-copilot40k stars
5,040

Security hardening reviewer for GitHub Actions workflow files (.github/workflows/*.yml). Reasons about the Actions threat model that pattern matchers and general code linters miss — untrusted-input script injection, privileged triggers running fork code, mutable action references, and over-scoped tokens. Use this skill when asked to review, audit, harden, or secure a GitHub Actions workflow, when writing a new workflow, or for any request like "is this workflow safe?", "review my CI for security issues", "why is pull_request_target dangerous here?", "pin my actions", or "lock down GITHUB_TOKEN permissions". Covers script injection via ${{ }} interpolation, pull_request_target / workflow_run privilege escalation, SHA-pinning of third-party actions, least-privilege permissions, GITHUB_ENV/GITHUB_OUTPUT injection, secret exposure, OIDC over long-lived credentials, and self-hosted runner exposure on public repositories.

Use this Skill: https://skilld.dev/gh/github/awesome-copilot/github-actions-hardening

This session only. Nothing lands on disk.

referencespermissions-and-tokens.md

≈686 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Permissions and Tokens

Every workflow run gets an automatic GITHUB_TOKEN. Its scope is the blast radius if a step is compromised, so scope it to the minimum.

The Default Is Too Broad

If a workflow has no permissions: block, it inherits the repository/organization default. On older or permissive repos that default is read/write to most scopes. A single injected command or malicious dependency then runs with the ability to push code, publish releases, or approve PRs.

Least-Privilege Recipe

Set a restrictive default at the top level, then elevate per job only where needed.

# Deny by default
permissions: {}

jobs:
  build:
    permissions:
      contents: read          # checkout only
    runs-on: ubuntu-latest
    steps: [...]

  comment:
    permissions:
      contents: read
      pull-requests: write    # this job posts a comment; nothing else
    runs-on: ubuntu-latest
    steps: [...]

Common scopes: contents, pull-requests, issues, actions, packages, id-token, deployments, checks, statuses. Each is read, write, or none.

Findings to Flag

  • No permissions: block anywhere → MEDIUM (inherits possibly-broad default).
  • permissions: write-all → HIGH.
  • A write scope the job's steps never use → HIGH (drop it).
  • Top-level write that should live on one job → MEDIUM (move it down).

OIDC Instead of Long-Lived Cloud Secrets

Storing static cloud keys (AWS_ACCESS_KEY_ID, etc.) as repo secrets means a leak is permanent until manually rotated. Prefer OpenID Connect: the workflow requests a short-lived token the cloud provider trusts, scoped to that repo/branch, expiring in minutes.

permissions:
  id-token: write     # required to request the OIDC token
  contents: read
jobs:
  deploy:
    runs-on: ubuntu-latest
    steps:
      - uses: aws-actions/configure-aws-credentials@<sha>
        with:
          role-to-assume: arn:aws:iam::123456789012:role/my-ci-role
          aws-region: us-east-1
      # no AWS_ACCESS_KEY_ID / AWS_SECRET_ACCESS_KEY secrets needed

The same pattern exists for Azure (azure/login), GCP (google-github-actions/auth), HashiCorp Vault, and others. On the cloud side, scope the trust policy to the specific repo and ideally a specific branch/environment so a fork or another repo cannot assume the role.

Secret Hygiene

  • Reference secrets only in the jobs that need them.
  • Never echo a secret or enable shell tracing (set -x) in a step that handles one.
  • Don't pass secrets into third-party actions you haven't pinned and reviewed.
  • Remember fork pull_request runs get no secrets — don't try to "fix" that by switching to pull_request_target (see triggers-and-privilege.md).

Source: SKILL.md on GitHub

No alerts3mo3 checks · Risk SAFE
  • Gen Agent Trust Hub3mo

    The skill is a specialized security auditor for GitHub Actions workflows. It provides correct and professional guidance on identifying script injection vulnerabilities, supply chain risks via mutable action references, and permission misconfigurations. No malicious code, exfiltration patterns, or obfuscation were detected.

  • Socket3mo

    No alerts

  • Snyk3mo

    Risk: LOW · No issues

Signed by skilld at 0bd4166. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 4 months ago

README badge

README badge for github/awesome-copilot/github-actions-hardening