CI Workflow Audit

Audit CI workflow files for supply-chain risk — unpinned actions, unpinned container images, pull_request-triggered jobs with secret access, curl-pipe-shell installers, and bare :latest tags. Produces a structured markdown report with file:line refs.

jmagly Updated

File contents

jmagly/ai-writing-guide/tree/main/agentic/code/plugins/security-engineering/skills/ci-workflow-audit commit f36e19557a

Frequently asked questions

npx skillmds@latest add jmagly-ai-writing-guide/ci-workflow-audit