github-actions-hardening
About
Security hardening reviewer for GitHub Actions workflow files (.github/workflows/*.yml). Reasons about the Actions threat model that pattern matchers and general code linters miss — untrusted-input script injection, privileged triggers running fork code, mutable action references, and over-scoped tokens. Use this skill when asked to review, audit, harden, or secure a GitHub Actions workflow, when writing a new workflow, or for any request like "is this workflow safe?", "review my CI for security issues", "why is pull_request_target dangerous here?", "pin my actions", or "lock down GITHUB_TOKEN permissions". Covers script injection via ${{ }} interpolation, pull_request_target / workflow_run privilege escalation, SHA-pinning of third-party actions, least-privilege permissions, GITHUB_ENV/GITHUB_OUTPUT injection, secret exposure, OIDC over long-lived credentials, and self-hosted runner exposure on public repositories.
Capabilities
The crawler did not record capability metadata for this resource. Inspect the endpoint directly to see what it exposes.
Provenance
- Discovered
- Relayed by agntcy
- Identifier
- urn:air:outshift.io:agntcy:github-actions-hardening
- Catalog host
- outshift.io · via agntcy registry
- Anchor check
- Not anchored
- Last crawled
- seen 1h ago
Discovered through outshift.io's registry, not anchored by StealthStack. We relay the listing as-is; we have not checked that the URN authority matches the publishing host. How trust works →