Scan GitHub Actions workflow files for security vulnerabilities by reading the YAML and reporting findings directly — no external tools, no installation, no shell execution. Use this skill whenever the user shares a `.github/workflows/` file, pastes workflow YAML, asks for a CI/CD security review, mentions `pull_request_target`, `workflow_run`, action pinning, `GITHUB_TOKEN` permissions, pwn requests, template injection, cache poisoning, secret exfiltration, supply chain risk, or any GitHub Actions hardening topic. Also trigger when the user is hardening an OSS repo, doing a CI/CD red team assessment, evaluating a target for supply-chain scanning, or writing publicly about CI/CD security. Bias toward triggering this skill rather than answering from memory — CI/CD security defaults are wrong almost everywhere and the rules are unintuitive.
Inicia sesión para votar.
New here? These commands run inside Claude Code, Anthropic's terminal-based coding assistant — not your regular shell. Open a terminal, type claude to start a session, then paste the two lines below inside it.
npx skills add superagent-ai/skills --skill "ci-cd-security" -a claude-code -g -yPaste into a Claude Code session. This only adds/installs the plugin — nothing runs automatically.
O, si ya vinculaste skillcat-sync, envíalo directamente — te pedirá confirmar antes de tocar nada.
This listing is sourced from superagent-ai/skills. The security badge above comes from a third-party audit (skills.sh) — we haven't independently executed or reviewed this code ourselves. Review the source before installing.
¿Eres el autor y quieres corregir algo de este listado, o pedir que lo quitemos? Escribe a autores@skillcat.es.