Magpie Workflow Security Audit

Read-only GitHub Actions workflow security audit for one repository, an explicit repository set, or a whole GitHub org. Runs `zizmor` to surface injection vulnerabilities, excessive permissions, unpinned external actions, and self-hosted-runner fork-secret leaks. Produces a grouped, prioritised finding report; never edits workflow files, opens PRs, or posts comments.

apache Updated

File contents

apache/airflow-steward/tree/main/skills/workflow-security-audit commit 8c611a4674

Frequently asked questions

npx skillmds@latest add apache/magpie-workflow-security-audit