ci-secure
Installation
SKILL.md
CI Secure
Scans .github/workflows/*.yml against the ten critical attack vectors
in references/security-patterns.md — each
a complete outsider → compromise path with real incidents behind it (the
selection criterion and rejection record:
references/why-these-ten.md). Every finding
renders with a "what an attacker could do" scenario; zero findings is a
first-class result. The skill asks which findings to fix and dispatches one
subagent per finding group. It never commits, pushes, or opens a PR
unasked — by default the user reviews the working-tree diff themselves.
Scope honesty (verbatim, in every report): Critical exploit-chain checks only — this is not a comprehensive audit.