Runner Security Reviewer

Assess a self-hosted runner pool (or a single runner image) against the org's runner-security baseline — ephemeral lifecycle, restricted network egress, runner-group scoping, OS image hardening, secret handling, log retention. Produces a posture report with current state vs expected per item. Use during runner-pool design review, after a runner-related incident, when planning a new restricted runner group for a regulated workload, or as part of quarterly GHAS posture audit.

themarmack b33c682 4.5 KB Updated

File contents

themarmack/research-bot/tree/main/.claude/skills/runner-security-reviewer commit b33c682e59

Frequently asked questions

npx skillmds@latest add themarmack/runner-security-reviewer