Audit Github Actions

Audit GitHub Actions workflows for supply-chain and CI/CD security vulnerabilities — script injection, expression injection, token exfiltration, unpinned actions, cache poisoning, and Shai-Hulud-class self-replicating worms. Use when the user asks to audit, review, or check the security of GitHub Actions, workflows, CI/CD pipelines, or asks about supply-chain risk, npm publish security, or Shai-Hulud.

franky47 Updated

File contents

franky47/dotfiles/tree/main/dot-claude/skills/audit-github-actions commit 6544e928fc

Frequently asked questions

npx skillmds@latest add franky47/audit-github-actions