actions-security-review
Reviews GitHub Actions workflows with actionlint and zizmor, then ranks findings by exploitable data flow and proposes behavior-aware fixes. Use when: reviewing Actions security, privileged triggers, expression or environment-file injection, token permissions, action pinning, vulnerable actions, reusable-workflow secrets, OIDC boundaries, artifacts, or self-hosted runners.
Pinned to revision a261dba717ef, so it is the text this page describes rather than whatever the author pushed since.
Files
- skills/actions-security-review/SKILL.md
- skills/actions-security-review/references/fix-patterns.md
- skills/actions-security-review/references/org-controls.md
- skills/actions-security-review/references/privileged-triggers.md
- skills/actions-security-review/references/report-template.md
Every link opens the file at its source, pinned to the revision this page describes.