Audit Actions

Audit a repository's GitHub Actions workflows for unsafe pull_request_target usage that can lead to supply chain compromise. Use when the user asks to audit workflows, review CI/CD security, check pwn request risk, harden Actions, or after a supply chain incident in a dependency. Also use proactively when reviewing any PR that touches .github/workflows/.

saschb2b eece0a0 6 files · 18.0 KB Updated

File contents

saschb2b/skills/tree/main/skills/engineering/audit-actions commit eece0a0f86

Frequently asked questions

npx skillmds@latest add saschb2b/audit-actions