Skip to content

austenstone/actions

v1.2.0MIT

GitHub Actions diagnosis and review skills for runtime failures, security, optimization, and architecture.

actions-security-review

Reviews GitHub Actions workflows with actionlint and zizmor, then ranks findings by exploitable data flow and proposes behavior-aware fixes. Use when: reviewing Actions security, privileged triggers, expression or environment-file injection, token permissions, action pinning, vulnerable actions, reusable-workflow secrets, OIDC boundaries, artifacts, or self-hosted runners.

Read SKILL.md at the source

Pinned to revision a261dba717ef, so it is the text this page describes rather than whatever the author pushed since.

Files

Every link opens the file at its source, pinned to the revision this page describes.