Gh Repo Security Audit

OpenSSF-aligned security posture audit across all repos in a GitHub account: default workflow token permissions, allowed-actions policy, branch protection, secret scanning + push protection, and Dependabot alerts. Reports WARN (fixable gaps) vs INFO (opinionated hardening). Read-only by default; the only optional mutation is enabling Dependabot alerts. Use when you ask: "repo security audit", "OpenSSF audit", "are Dependabot alerts on?", "GitHub hardening check", "repo セキュリティ監査", "Actions セキュリティ横断". DO NOT USE FOR: writing code, changing branch protection automatically, or the PR-approval toggle (use gh-pr-perm-audit for that).

thinkyou0714 Updated

File contents

thinkyou0714/github-flow-kit/tree/main/gh-repo-security-audit commit 900be058e0

Frequently asked questions

npx skillmds@latest add thinkyou0714/gh-repo-security-audit