skills/skills.volces.com/github-actions-workflow-hardening-audit

github-actions-workflow-hardening-audit

Installation
SKILL.md

GitHub Actions Workflow Hardening Audit

Use this skill to statically audit .github/workflows/*.yml files before risky defaults leak into production CI.

What this skill does

  • Scans workflow YAML files and scores hardening risk per file
  • Flags jobs missing timeout-minutes
  • Flags missing permissions declarations (workflow-level or job-level)
  • Optionally flags missing concurrency controls
  • Flags floating uses: refs (@main, @master, @latest, major-only tags like @v4)
  • Supports file/event regex filtering for targeted triage in large monorepos
  • Raises severity (ok / warn / critical) and can fail CI gates
Installs
3
First Seen
Apr 23, 2026
github-actions-workflow-hardening-audit from skills.volces.com