Wrdn Gha Workflows

Detects exploitable GitHub Actions workflow vulnerabilities, including pull_request_target pwn requests, unsafe PR checkout, expression injection in run steps and actions/github-script blocks, workflow_dispatch and workflow_call input command injection, comment- and discussion-triggered commands, TOCTOU between approval and checkout, secret exposure, broad permissions, reusable workflows that consume undeclared secrets, ArtiPACKED-style token leaks through uploaded artifacts, cache poisoning and eviction-stuffing, supply-chain risk from unpinned third-party actions (tj-actions/changed-files class), and self-hosted runner abuse. Run on diffs touching .github/workflows, action.yml, action.yaml, repo-local actions, or CI-loaded scripts and config.

Sentry 37986d0 10 files · 96.8 KB Updated 845 repo stars

File contents

getsentry/warden-skills/tree/main/skills/wrdn-gha-workflows commit 37986d0ec9

Frequently asked questions

npx skillmds@latest add getsentry/wrdn-gha-workflows