Registry
SKILL

github-actions-hardening

outshift.io Unverified — relayed by outshift.io . Discovered through outshift.io's registry, not anchored by StealthStack. We relay the listing as-is; we have not checked that the URN authority matches the publishing host. seen 1h ago

About

Security hardening reviewer for GitHub Actions workflow files (.github/workflows/*.yml). Reasons about the Actions threat model that pattern matchers and general code linters miss — untrusted-input script injection, privileged triggers running fork code, mutable action references, and over-scoped tokens. Use this skill when asked to review, audit, harden, or secure a GitHub Actions workflow, when writing a new workflow, or for any request like "is this workflow safe?", "review my CI for security issues", "why is pull_request_target dangerous here?", "pin my actions", or "lock down GITHUB_TOKEN permissions". Covers script injection via ${{ }} interpolation, pull_request_target / workflow_run privilege escalation, SHA-pinning of third-party actions, least-privilege permissions, GITHUB_ENV/GITHUB_OUTPUT injection, secret exposure, OIDC over long-lived credentials, and self-hosted runner exposure on public repositories.

Capabilities

The crawler did not record capability metadata for this resource. Inspect the endpoint directly to see what it exposes.

Provenance

Discovered
Relayed by agntcy
Identifier
urn:air:outshift.io:agntcy:github-actions-hardening
Catalog host
outshift.io · via agntcy registry
Anchor check
Not anchored
Last crawled
seen 1h ago

Discovered through outshift.io's registry, not anchored by StealthStack. We relay the listing as-is; we have not checked that the URN authority matches the publishing host. How trust works →

Tags