Ci Cd Security

作者 superagent-ai0da315b873ed無授權條款77 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫7 週前更新

Scan GitHub Actions workflow files for security vulnerabilities by reading the YAML and reporting findings directly — no external tools, no installation, no shell execution. Use this skill whenever the user shares a `.github/workflows/` file, pastes workflow YAML, asks for a CI/CD security review, mentions `pull_request_target`, `workflow_run`, action pinning, `GITHUB_TOKEN` permissions, pwn requests, template injection, cache poisoning, secret exfiltration, supply chain risk, or any GitHub Actions hardening topic. Also trigger when the user is hardening an OSS repo, doing a CI/CD red team assessment, evaluating a target for supply-chain scanning, or writing publicly about CI/CD security. Bias toward triggering this skill rather than answering from memory — CI/CD security defaults are wrong almost everywhere and the rules are unintuitive.

新增到 SourceWeft 工作區

  1. 在儀表板中開啟該技能,並將它新增到工作區。
  2. 為需要使用它的對話啟用該技能。

該技能僅含說明:不附帶任何可執行的腳本。

新增到 SourceWeft

系統會先要求你登入,然後直接帶你回到這個技能。

讓你的代理程式來安裝

把這段提示詞貼上到 Claude Code、Codex、Cursor 或其他能執行命令的代理程式中,也可以貼上到 SourceWeft 對話裡。代理程式會閱讀這個技能的安裝說明,向你展示它的來源、授權條款和腳本情況,在你同意後用 SourceWeft CLI 安裝。

閱讀 https://sourceweft.com/skills/gh-superagent-ai-skills-ci-cd-security/install.md 中的說明,按說明安裝這個技能。安裝前先告訴我它的來源、授權條款以及是否附帶腳本,等我確認。修改我電腦上的其他任何內容之前也要先問我。

檢視代理程式所遵循的安裝說明

用命令列自行安裝

適用於 Claude Code、Codex、Cursor 及其他本機代理程式。SourceWeft CLI 會從原始碼儲存庫中取得此處掃描過的那次提交,並根據掃描時記錄的雜湊值逐一驗證每個檔案。只要有任何不一致,就不會寫入任何內容。

npx @sourceweft/cli skills install gh-superagent-ai-skills-ci-cd-security

新增 --agent claude-code、codex、cursor 或 universal 來選擇安裝給哪個代理程式(預設為 Claude Code)。

上游安裝器——未經 SourceWeft 驗證

開源的 skills 安裝器會取得同一個固定的提交,但不會根據 SourceWeft 記錄的雜湊值驗證檔案。

npx skills add https://github.com/superagent-ai/skills/tree/0da315b873ed141025fa601ed6e0ebe0c878d5af/skills/ci-cd-security

來源與署名

來源:superagent-ai/skills位於skills/ci-cd-security提交0da315b

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架