All skills
github avatar

/github-actions-hardening

@0bd4166 official
by githubgithub/awesome-copilot40k stars
5,040

Security hardening reviewer for GitHub Actions workflow files (.github/workflows/*.yml). Reasons about the Actions threat model that pattern matchers and general code linters miss — untrusted-input script injection, privileged triggers running fork code, mutable action references, and over-scoped tokens. Use this skill when asked to review, audit, harden, or secure a GitHub Actions workflow, when writing a new workflow, or for any request like "is this workflow safe?", "review my CI for security issues", "why is pull_request_target dangerous here?", "pin my actions", or "lock down GITHUB_TOKEN permissions". Covers script injection via ${{ }} interpolation, pull_request_target / workflow_run privilege escalation, SHA-pinning of third-party actions, least-privilege permissions, GITHUB_ENV/GITHUB_OUTPUT injection, secret exposure, OIDC over long-lived credentials, and self-hosted runner exposure on public repositories.

Use this Skill: https://skilld.dev/gh/github/awesome-copilot/github-actions-hardening

This session only. Nothing lands on disk.

referencestriggers-and-privilege.md

≈850 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Triggers and Privilege

The single most important question for workflow security is: can an outside contributor trigger this workflow, and if so, what token and secrets does it get? GitHub answers this differently per trigger.

Trust Matrix

Trigger Who can fire it GITHUB_TOKEN Secrets available Risk
push Repo collaborators read/write yes Low — trusted authors
pull_request (same-repo branch) Collaborators read/write yes Low
pull_request (from a fork) Anyone read-only no Low by design — even malicious code can't steal anything
pull_request_target Anyone with a fork read/write yes High — runs in base-repo context
workflow_run Fires after another workflow read/write yes High
issue_comment, issues Anyone read/write yes High

The trap: pull_request from a fork is safe because GitHub deliberately strips the token down and withholds secrets. Maintainers who find that "the secrets don't work on fork PRs" often switch to pull_request_target to get them back — and in doing so hand a write token and every secret to arbitrary contributors.

Why pull_request_target Is Dangerous

pull_request_target checks out the base repository's workflow definition (so a fork can't change what runs), but it runs with full privileges. The danger is when the workflow then explicitly checks out the fork's code and executes it:

# DANGEROUS — RCE with a write token + secrets
on: pull_request_target
jobs:
  build:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@<sha>
        with:
          ref: ${{ github.event.pull_request.head.sha }}   # fork's code
      - run: npm install && npm test                        # runs the fork's code + scripts

npm install alone runs arbitrary lifecycle scripts from the PR. With pull_request_target those scripts can read secrets.* and push commits with the write token.

The Safe Two-Workflow Pattern

Split responsibilities. An unprivileged workflow runs the untrusted code; a privileged workflow consumes only the trusted output.

# 1) Unprivileged: runs untrusted code, no secrets, read-only token
name: PR Build
on: pull_request
permissions:
  contents: read
jobs:
  build:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@<sha>
      - run: npm ci && npm run build
      - uses: actions/upload-artifact@<sha>
        with: { name: pr, path: dist/ }
# 2) Privileged: triggered by the first, never runs fork code
name: PR Comment
on:
  workflow_run:
    workflows: ["PR Build"]
    types: [completed]
permissions:
  pull-requests: write
jobs:
  comment:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/download-artifact@<sha>   # data only, not executed
      # post results, using the trusted token — but never execute the artifact

Rules

  • Treat pull_request_target, workflow_run, issue_comment, and issues as privileged.
  • In a privileged workflow, never check out and execute PR/fork code.
  • If you only need to label, comment, or triage based on metadata, that is fine — just don't run the contributor's code.
  • Prefer pull_request (with its safe read-only/no-secrets defaults) whenever possible.

Source: SKILL.md on GitHub

No alerts3mo3 checks · Risk SAFE
  • Gen Agent Trust Hub3mo

    The skill is a specialized security auditor for GitHub Actions workflows. It provides correct and professional guidance on identifying script injection vulnerabilities, supply chain risks via mutable action references, and permission misconfigurations. No malicious code, exfiltration patterns, or obfuscation were detected.

  • Socket3mo

    No alerts

  • Snyk3mo

    Risk: LOW · No issues

Signed by skilld at 0bd4166. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 20 hours ago.

Activeupdated 4 months ago

README badge

README badge for github/awesome-copilot/github-actions-hardening