Audit GitHub Actions for privilege and supply-chain risks with zizmor

Run a focused security pass on GitHub Actions workflows before merge so token misuse, dangerous permissions, and unpinned actions are caught early.

agentskillexchange Updated 28 repo stars

File contents

Audit GitHub Actions for privilege and supply-chain risks with zizmor

Run a focused security pass on GitHub Actions workflows before merge so token misuse, dangerous permissions, and unpinned actions are caught early.

Prerequisites

Python 3.9+ or prebuilt zizmor binary, access to the target repository

Installation

Basic usage or getting-started notes:

Documentation

Source

agentskillexchange/skills/tree/main/skills/audit-github-actions-for-privilege-and-supply-chain-risks-with-zizmor commit b68df73ba4

Frequently asked questions

npx skillmds@latest add agentskillexchange/audit-github-actions-for-privilege-and-supply-chain-risks-wi