Github Org Audit Runner

Audit a GitHub organization's admin-surface settings — SAML / SCIM, EMU posture, base permissions, secret scanning + push-protection org defaults, allowed Actions list, runner groups, repository creation policies, IP allow-list — against the org's baseline. Uses `gh api` for live inspection where authenticated; falls back to a structured manual-checklist a human admin can walk through in the UI. Produces a posture report with `current_state` vs `expected_state` per item, severity, and remediation. Use during quarterly admin reviews, before audit conversations, or when troubleshooting a "why can't users do X" complaint that might be an org-wide policy.

themarmack 61bad0e 7.4 KB Updated

File contents

themarmack/research-bot/tree/main/.claude/skills/github-org-audit-runner commit 61bad0ef87

Frequently asked questions

npx skillmds@latest add themarmack/github-org-audit-runner