
workflow-security-review
by tom171296
Craft beer company that suits their customers reviews to create new craft beer flavours
SKILL.md
name: Workflow Security Review description: Guide for reviewing GitHub Actions for security vulnerabilities. allowed-tools: mcp_github-mcp_get_ref, mcp_github-mcp_list_tags, mcp_github-mcp_get_repository
Workflow Security Review
This skill analyzes GitHub Actions workflows for security vulnerabilities and misconfigurations that could lead to code injection, privilege escalation, or credential exposure.
Available MCP Tools
| Tool | Purpose |
|---|---|
mcp_github-mcp_get_ref | Retrieves a Git reference, useful for verifying action SHAs |
mcp_github-mcp_list_tags | Lists all tags for a given repository, useful for identifying action versions |
mcp_github-mcp_get_repository | Fetches repository details, useful for context on workflows |
When to use this skill
Use this skill when you need to:
- Validate the security of your GitHub Actions workflows
- Review pull requests that modify workflow files
- Identify potential security risks in your CI/CD pipelines
- Ensure compliance with security best practices in your automation processes
- Audit workflows before deploying to production
- Investigate security incidents involving GitHub Actions
Analyzing GitHub Actions
Step-by-step Analysis Process
-
Locate Workflow Files
- Check
.github/workflows/directory for all*.ymland*.yamlfiles
- Check
-
Review Trigger Events
- Identify workflows triggered by
pull_request_target,workflow_run, orissue_comment - These events have elevated privileges and access to secrets
- Verify that untrusted code is not executed with these triggers
- Identify workflows triggered by
-
Inspect Action Pinning
- Check if third-party actions use commit SHAs instead of tags
- Example:
actions/checkout@a12b3c4...✅ vsactions/checkout@v4⚠️
-
Analyze Script Injection Risks
- Look for
${{ }}expressions inrun:blocks - Check for unsafe context variables in scripts
- Identify untrusted input from:
github.event.issue.title,github.event.comment.body,github.event.pull_request.title,github.head_ref
- Look for
-
Review Permissions
- Verify
permissions:are set at job or workflow level - Ensure least privilege (use
contents: readas default) - Flag workflows without explicit permissions (inherit all by default)
- Verify
-
Check Secret Handling
- Ensure secrets are not logged or exposed in outputs
- Verify secrets are not used in pull requests from forks
- Check for hardcoded credentials or tokens
Additional resources
For detailed vulnerability patterns, secure code examples, best practices, and remediation guidance, see reference.md.
Score
Total Score
Based on repository quality metrics
SKILL.mdファイルが含まれている
ライセンスが設定されている
100文字以上の説明がある
GitHub Stars 100以上
3ヶ月以内に更新がある
10回以上フォークされている
オープンIssueが50未満
プログラミング言語が設定されている
1つ以上のタグが設定されている
Reviews
Reviews coming soon