github-actions-workflow-hardening-audit
Installation
SKILL.md
GitHub Actions Workflow Hardening Audit
Use this skill to statically audit .github/workflows/*.yml files before risky defaults leak into production CI.
What this skill does
- Scans workflow YAML files and scores hardening risk per file
- Flags jobs missing
timeout-minutes - Flags missing
permissionsdeclarations (workflow-level or job-level) - Optionally flags missing
concurrencycontrols - Flags floating
uses:refs (@main,@master,@latest, major-only tags like@v4) - Supports file/event regex filtering for targeted triage in large monorepos
- Raises severity (
ok/warn/critical) and can fail CI gates