cicd-supply-chain
Installation
SKILL.md
CI/CD Pipeline Poisoning & Supply-Chain Attacks
When to Activate
- Auditing or attacking GitHub Actions / GitLab CI / Jenkins pipelines for code execution
- Hunting
pull_request_target/workflow_run"pwn requests" and Poisoned Pipeline Execution (PPE) - Assessing compromised third-party Actions, mutable version tags, and Actions cache poisoning
- Dependency confusion, typo/slopsquatting, and malicious package/install-hook payloads
- Self-hosted / non-ephemeral runner abuse and runner backdoors
- CI secret exfiltration and OIDC cloud-role (AWS/GCP/Azure) trust-policy abuse
- Validating SLSA build provenance and signing gates (defense / blue-team validation)