Github Actions Injection

GitHub Actions ${{ }} expression injection — attacker-controlled context (issue/PR title, body, branch name, commit message) substituted into run: steps, unsafe pull_request_target + PR-head checkout, GITHUB_TOKEN scope abuse, artifact/cache poisoning, action tag-vs-SHA pinning.

purpleailab aabb7d5 7.5 KB Updated

File contents

purpleailab/decepticon/tree/main/packages/decepticon/decepticon/skills/standard/exploit/cicd/github-actions-injection commit aabb7d53c6

Frequently asked questions

npx skillmds@latest add purpleailab/github-actions-injection