smithery/tom171296

Workflow Security Review

Guide for reviewing GitHub Actions for security vulnerabilities.

Installation

$ npx skills add smithery/tom171296 --skill workflow-security-review

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Skill metadata

Parsed from SKILL.md frontmatter.

Allowed toolsmcp_github-mcp_get_ref, mcp_github-mcp_list_tags, mcp_github-mcp_get_repository

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 2,668 B
  • docs SUMMARY.md 96 B

History

  1. First recorded snapshot · 0 installs

SKILL.md

Workflow Security Review

This skill analyzes GitHub Actions workflows for security vulnerabilities and misconfigurations that could lead to code injection, privilege escalation, or credential exposure.

Available MCP Tools

Tool Purpose
mcpgithub-mcpget_ref Retrieves a Git reference, useful for verifying action SHAs
mcpgithub-mcplist_tags Lists all tags for a given repository, useful for identifying action versions
mcpgithub-mcpget_repository Fetches repository details, useful for context on workflows

When to use this skill

Use this skill when you need to:

  • Validate the security of your GitHub Actions workflows
  • Review pull requests that modify workflow files
  • Identify potential security risks in your CI/CD pipelines
  • Ensure compliance with security best practices in your automation processes
  • Audit workflows before deploying to production
  • Investigate security incidents involving GitHub Actions

Analyzing GitHub Actions

Step-by-step Analysis Process

  1. Locate Workflow Files

- Check .github/workflows/ directory for all .yml and .yaml files

  1. Review Trigger Events

- Identify workflows triggered by pullrequesttarget, workflowrun, or issuecomment - These events have elevated privileges and access to secrets - Verify that untrusted code is not executed with these triggers

  1. Inspect Action Pinning

- Check if third-party actions use commit SHAs instead of tags - Example: actions/checkout@a12b3c4... ✅ vs actions/checkout@v4 ⚠️

  1. Analyze Script Injection Risks

- Look for ${{ }} expressions in run: blocks - Check for unsafe context variables in scripts - Identify untrusted input from: github.event.issue.title, github.event.comment.body, github.event.pullrequest.title, github.headref

  1. Review Permissions

- Verify permissions: are set at job or workflow level - Ensure least privilege (use contents: read as default) - Flag workflows without explicit permissions (inherit all by default)

  1. Check Secret Handling

- Ensure secrets are not logged or exposed in outputs - Verify secrets are not used in pull requests from forks - Check for hardcoded credentials or tokens

Additional resources

For detailed vulnerability patterns, secure code examples, best practices, and remediation guidance, see [reference.md](./reference.md).