Audit GitHub Actions for privilege and supply-chain risks with zizmor
Run a focused security pass on GitHub Actions workflows before merge so token misuse, dangerous permissions, and unpinned actions are caught early.
Prerequisites
Python 3.9+ or prebuilt zizmor binary, access to the target repository
Installation
Choose whichever fits your setup:
- Copy this skill folder into your local skills directory.
- Clone the repo and symlink or copy the skill into your agent workspace.
- Add the repo as a git submodule if you manage shared skills centrally.
- Install it through your internal provisioning or packaging workflow.
- Download the folder directly from GitHub and place it in your skills collection.
Install command or upstream instructions:
Install from the project documentation, then run `zizmor` against the repository or workflow files you want to review before merge or release.