GitHub Actions Security Review
Trace externally reachable GitHub Actions attack paths involving fork code, expressions, permissions, and workflow dependencies.
- Purpose
- Database and code review
- Author / publisher
- Sentry
- License
- Apache-2.0 · License guidance
- Version
- d18b7aa8ba87.bb1
- Access
- Free download. External tools and services may have separate costs.
- Declared clients
- Claude Code, Codex, Cursor
Source & package
16 files · 0 script/code files. License file detected.
Current package SHA-256
3c1f5e9843c76f71daa14ca669700d4839e90ff7be8113cc3934299692746622Tools & requirements
Access to workflow YAML, local actions, and relevant repository configuration; a client able to read and search project files.
Review only repositories you are authorized to inspect. Keep examples inert; do not run exploit payloads, expose tokens, or execute untrusted pull-request code. Agent review is not a security certification. Core frontmatter was adapted by BB Skills for the existing namespace directory; unchanged original SKILL.md is archived. This does not imply client execution was tested.
Evidence & limits
Source review checked 2026-10-03. Full skill/agent runtime evaluation has not been performed.
0 current outcome records. No published pass/fail record matches this version and checksum.