OpenHound GitHub / GitHound
Use this skill for OpenHound GitHub OpenGraph query design and attack-path triage with GitHound-collected GitHub data.
Required context
- Authorized GitHub enterprises, organizations, and repositories.
- Whether GitHound/OpenHound GitHub schema/data is loaded.
- Whether SAML external identity, SCIM, Azure, Okta, or other linked identity data is available.
- Target repositories, teams, users, actions policies, environments, secrets, PATs, apps, or cloud identities.
Workflow
- Read
../../references/docs/bloodhound-query-methodology.md,../../references/docs/openhound-github-methodology.md, and../../references/docs/collector-source-index.md. - If SCIM, SAML, SSO, Okta, Azure, or external identity links are relevant, read
../../references/docs/scim-methodology.mdand inspect the small GitHound examples under../../references/examples/githound/samples/. - Search
../../references/query-indexes/openhound-github.mdand../../references/examples/example-cypher.mdfor a saved-query starting point. - Inspect the referenced JSON snapshot and adapt parameters safely.
- Preserve
GH_labels/edges,SCIM_*bridge labels/edges, and permission-inheritance path shape. - Separate posture checks from attack paths and list false-positive validation steps.
Common pivots
- GitHub users/teams to repo admin/write access.
- Branch protection bypass and dangerous branch permissions.
- Actions policy, SHA pinning, workflow dispatch, runner, and secret exfiltration risk.
- Secrets/variables scope exposure and secret scanning alert metadata.
- App installations and PATs with broad repository access.
- GitHub OIDC to Azure federated identity credentials.
- External identities without SCIM and SCIM-provisioned identities mapped to GitHub users/teams.
Output
Use the shared output contract from $bloodhound-query and include GitHub-specific caveats such as enterprise/org coverage, Actions settings collection, SAML/SCIM data availability, secret metadata limitations, and linked-identity confidence.