agentic-actions-auditor
Audits GitHub Actions workflows for security vulnerabilities in AI agent integrations including Claude Code Action, Gemini CLI, OpenAI Codex, and GitHub AI Inference. Detects attack vectors where attacker-controlled input reaches AI agents running in CI/CD pipelines, including env var intermediary patterns, direct expression injection, dangerous sandbox configurations, and wildcard user allowlists. Use when reviewing workflow files that invoke AI coding agents, auditing CI/CD pipeline security f
Security Assessment
Detected risks:
About agentic-actions-auditor
The agentic-actions-auditor skill is designed to perform static security analysis on GitHub Actions workflows that integrate AI coding agents such as Claude Code Action, Gemini CLI, OpenAI Codex, and GitHub AI Inference. Its primary goal is to identify security vulnerabilities where attacker-controlled input could reach these AI agents within CI/CD pipelines. This addresses the critical risk of prompt injection attacks, misconfigured sandboxes, and unsafe workflow configurations that could lead to unauthorized data access or execution of malicious commands.
The skill provides capabilities for discovering workflow files both locally and from remote GitHub repositories, identifying steps that invoke AI agents, and tracing cross-file references to composite actions and reusable workflows. It detects attack vectors including environment variable intermediary patterns, direct expression injections, dangerous sandbox settings, and overly permissive user allowlists. The skill also guides users in capturing security-relevant configuration, evaluating triggers that expose workflows to external input, and reviewing data flows from GitHub event context through `env:` blocks to AI prompts.
This skill is useful for security engineers, DevOps professionals, and developers responsible for maintaining secure CI/CD pipelines involving AI agents. Typical use cases include auditing repositories for AI agent security, evaluating agent configurations, reviewing workflows for exposure to untrusted inputs, and identifying potential prompt injection risks. It is intended strictly for static analysis and does not modify workflow files, perform runtime testing, or support non-GitHub CI/CD platforms.
FAQ
Which AI agents does this skill support?
It supports auditing workflows that integrate Claude Code Action, Gemini CLI, OpenAI Codex, and GitHub AI Inference.
Can this skill analyze workflows for CI/CD systems other than GitHub Actions?
No, it is specifically designed for GitHub Actions workflows and does not support Jenkins, GitLab CI, CircleCI, or other CI/CD systems.
Does the skill automatically fix security issues in workflows?
No, it performs static analysis and reports findings. It does not modify or auto-fix workflow files.
Can this skill detect runtime prompt injection attacks?
No, it focuses on static security analysis and identifying potential attack vectors in workflow configuration, not exploiting them at runtime.
Is it necessary for workflows to use AI agent actions to use this skill?
Yes, the skill is intended for workflows that invoke AI coding agents. For workflows without AI agents, general GitHub Actions security tools should be used.
All Files
13 filesInstall agentic-actions-auditor
Quick Setup:
- Copy the skill folder to
.claude/skills/ - Claude will automatically detect and use the skill
Repository
trailofbits/skills