Auditing Cicd Oidc Trust

Audit continuous-integration pipelines for the trust they extend to untrusted input: workflows that run on incoming change requests from forks while holding repository secrets, steps that let attacker-controlled content reach a privileged command, and cloud role trust conditions that accept a pipeline's short-lived token too broadly. Covers secret and token exposure on fork-triggered runs, poisoned-pipeline execution, and over-broad trust on the identity claim a pipeline presents to a cloud account. Use when reviewing CI/CD configuration, pipeline identity, or the boundary between a build and the cloud it can reach. An exploitable token or command from untrusted input is the finding.

UnboundCompute eb25b41 7.2 KB Updated

File contents

UnboundCompute/security-agent-skills/tree/main/skills/auditing-cicd-oidc-trust commit eb25b414f8

Frequently asked questions

npx skillmds@latest add unboundcompute/auditing-cicd-oidc-trust