All skills
github avatar

/github-actions-hardening

@0bd4166 official
by githubgithub/awesome-copilot40k stars
5,040

Security hardening reviewer for GitHub Actions workflow files (.github/workflows/*.yml). Reasons about the Actions threat model that pattern matchers and general code linters miss — untrusted-input script injection, privileged triggers running fork code, mutable action references, and over-scoped tokens. Use this skill when asked to review, audit, harden, or secure a GitHub Actions workflow, when writing a new workflow, or for any request like "is this workflow safe?", "review my CI for security issues", "why is pull_request_target dangerous here?", "pin my actions", or "lock down GITHUB_TOKEN permissions". Covers script injection via ${{ }} interpolation, pull_request_target / workflow_run privilege escalation, SHA-pinning of third-party actions, least-privilege permissions, GITHUB_ENV/GITHUB_OUTPUT injection, secret exposure, OIDC over long-lived credentials, and self-hosted runner exposure on public repositories.

Use this Skill: https://skilld.dev/gh/github/awesome-copilot/github-actions-hardening

This session only. Nothing lands on disk.

referencesreport-format.md

≈480 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Report Format

Use this structure for every workflow hardening review.

1. Summary Table (always first)

GitHub Actions Hardening — <workflow file(s) reviewed>

| Severity   | Count |
| ---------- | ----- |
| 🔴 CRITICAL | 1     |
| 🟠 HIGH     | 2     |
| 🟡 MEDIUM   | 1     |
| 🔵 LOW      | 1     |
| ⚪ INFO     | 0     |

If nothing was found: No issues found. Checked: triggers, injection sinks, permissions, action pinning, secret handling.

2. Findings (grouped by issue type, not by file)

For each finding use a card:

### 🔴 CRITICAL — Script injection via PR title on a privileged trigger

File: .github/workflows/triage.yml  (line 14)
Trigger: pull_request_target

Offending code:
    - run: echo "New PR: ${{ github.event.pull_request.title }}"

Risk: pull_request_target runs with a read/write token and repository secrets, and any
contributor can open a PR with a title like  "; <attacker-command> #  which is executed as shell.
This allows secret exfiltration and pushes with the workflow token.

Fix:
    - env:
        PR_TITLE: ${{ github.event.pull_request.title }}
      run: echo "New PR: $PR_TITLE"

Confidence: High

3. Remediation Blocks

Every CRITICAL and HIGH finding includes a concrete before/after. Preserve the author's indentation, step names, and surrounding structure — change only what fixes the issue, and add a one-line comment explaining the change where it isn't obvious.

4. Closing Note

End with the explicit line:

Review each change before committing. Nothing has been modified.

Style Rules

  • Quote the exact offending line and give its location.
  • Explain risk in plain English — what an attacker actually does, not just the rule name.
  • Per-finding confidence: High / Medium / Low.
  • Don't inflate severity: a fork pull_request (read-only token, no secrets) running untrusted code is not CRITICAL on its own.

Source: SKILL.md on GitHub

No alerts3mo3 checks · Risk SAFE
  • Gen Agent Trust Hub3mo

    The skill is a specialized security auditor for GitHub Actions workflows. It provides correct and professional guidance on identifying script injection vulnerabilities, supply chain risks via mutable action references, and permission misconfigurations. No malicious code, exfiltration patterns, or obfuscation were detected.

  • Socket3mo

    No alerts

  • Snyk3mo

    Risk: LOW · No issues

Signed by skilld at 0bd4166. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 20 hours ago.

Activeupdated 4 months ago

README badge

README badge for github/awesome-copilot/github-actions-hardening