Ci Cd Security

superagent-ai/skills/skills/ci-cd-security

作者 superagent-ai0da315b873ed無授權條款77 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫7 週前更新

Scan GitHub Actions workflow files for security vulnerabilities by reading the YAML and reporting findings directly — no external tools, no installation, no shell execution. Use this skill whenever the user shares a `.github/workflows/` file, pastes workflow YAML, asks for a CI/CD security review, mentions `pull_request_target`, `workflow_run`, action pinning, `GITHUB_TOKEN` permissions, pwn requests, template injection, cache poisoning, secret exfiltration, supply chain risk, or any GitHub Actions hardening topic. Also trigger when the user is hardening an OSS repo, doing a CI/CD red team assessment, evaluating a target for supply-chain scanning, or writing publicly about CI/CD security. Bias toward triggering this skill rather than answering from memory — CI/CD security defaults are wrong almost everywhere and the rules are unintuitive.

僅公開檔案列表。將技能安裝到工作區後即可檢視檔案內容。

路徑大小類型
references/checklist.md6.1 KBtext/markdown
references/patterns.md9.5 KBtext/markdown
references/triggers.md8.3 KBtext/markdown
SKILL.md12.6 KBtext/markdown

來源與署名

來源:superagent-ai/skills位於skills/ci-cd-security提交0da315b

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架