# Audit GitHub Actions for privilege and supply-chain risks with zizmor

> Run a focused security pass on GitHub Actions workflows before merge so token misuse, dangerous permissions, and unpinned actions are caught early.

- Skill: `agentskillexchange/audit-github-actions-for-privilege-and-supply-chain-risks-wi` (Agent Skill)
- Install (CLI): `npx skillmds@latest add agentskillexchange/audit-github-actions-for-privilege-and-supply-chain-risks-wi`
- Raw SKILL.md: https://api.skillmd.com/api/skills/agentskillexchange/audit-github-actions-for-privilege-and-supply-chain-risks-wi/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security
- Author: agentskillexchange (https://skillmd.com/u/agentskillexchange)
- Updated: 2026-09-08
- Page: https://skillmd.com/skills/agentskillexchange/audit-github-actions-for-privilege-and-supply-chain-risks-wi

---


# Audit GitHub Actions for privilege and supply-chain risks with zizmor

Run a focused security pass on GitHub Actions workflows before merge so token misuse, dangerous permissions, and unpinned actions are caught early.

## Prerequisites

Python 3.9+ or prebuilt zizmor binary, access to the target repository

## Installation

Basic usage or getting-started notes:
- [detailed usage recipes].
- [detailed usage recipes]: https://docs.zizmor.sh/usage/

- Source: https://github.com/zizmorcore/zizmor
- Extracted from upstream docs: https://raw.githubusercontent.com/zizmorcore/zizmor/HEAD/README.md

## Documentation

- https://woodruffw.github.io/zizmor/

## Source

- [Agent Skill Exchange](https://agentskillexchange.com/skills/audit-github-actions-for-privilege-and-supply-chain-risks-with-zizmor/)

