CI Agent Hardening

Audit and harden GitHub Actions workflows against prompt injection, pull_request_target exploits (Pwn Requests), expression injection, cache poisoning, credential theft, and supply chain attacks. Based on Clinejection and hackerbot-claw campaigns. Use when reviewing CI/CD security, securing AI agent workflows, hardening publishing pipelines, or checking for GitHub Actions misconfigurations. Also covers slash command authorization, CLAUDE.md protection, and network egress. NOT for general CI/CD optimization or non-security workflow issues.

stacklok d56b021 3 files · 29.2 KB Updated

File contents

stacklok/toolhive-catalog/tree/main/registries/toolhive/skills/ci-agent-hardening/skill commit d56b0213b0

Frequently asked questions

npx skillmds@latest add stacklok/ci-agent-hardening