Audits GitHub Actions workflows for security vulnerabilities in AI agent integrations including Claude Code Action, Gemini CLI, OpenAI Codex, and GitHub AI Inference. Detects attack vectors where attacker-controlled input reaches AI agents running in CI/CD pipelines, including env var intermediary patterns, direct expression injection, dangerous sandbox configurations, and wildcard user allowlists. Use when reviewing workflow files that invoke AI coding agents, auditing CI/CD pipeline security for prompt injection risks, or evaluating agentic action configurations.
Inicia sesión para votar.
New here? These commands run inside Claude Code, Anthropic's terminal-based coding assistant — not your regular shell. Open a terminal, type claude to start a session, then paste the two lines below inside it.
npx skills add trailofbits/skills --skill "agentic-actions-auditor" -a claude-code -g -yPaste into a Claude Code session. This only adds/installs the plugin — nothing runs automatically.
O, si ya vinculaste skillcat-sync, envíalo directamente — te pedirá confirmar antes de tocar nada.
This listing is sourced from trailofbits/skills. The security badge above comes from a third-party audit (skills.sh) — we haven't independently executed or reviewed this code ourselves. Review the source before installing.
¿Eres el autor y quieres corregir algo de este listado, o pedir que lo quitemos? Escribe a autores@skillcat.es.