All Agent Skills

Development & Engineering

github-actions-hardening

Github Actions Hardening is a source-indexed Agent Skill for development & engineering work. Based on the SKILL.md description, it focuses on security hardening reviewer for github actions workflow files (.github/workflows/.yml). Use the linked GitHub file to confirm scope and prerequisites before enabling it.

Read original SKILL.md
Review it in your own environment.

AI Vitamin indexes this source file; it does not certify safety, quality, compatibility, permissions, or outcomes.

What this Skill does

Github Actions Hardening is a source-indexed Agent Skill for development & engineering work. Based on the SKILL.md description, it focuses on security hardening reviewer for github actions workflow files (.github/workflows/.yml). Use the linked GitHub file to confirm scope and prerequisites before enabling it.

What the author says

Security hardening reviewer for GitHub Actions workflow files (.github/workflows/*.yml). Reasons about the Actions threat model that pattern matchers and general code linters miss — untrusted-input script injection, privileged triggers running fork code, mutable action references, and over-scoped tokens. Use this skill when asked to review, audit, harden, or secure a GitHub Actions workflow, when writing a new workflow, or for any request like "is this workflow safe?", "review my CI for security issues", "why is pull_request_target dangerous here?", "pin my actions", or "lock down GITHUB_TOKEN permissions". Covers script injection via ${{ }} interpolation, pull_request_target / workflow_run privilege escalation, SHA-pinning of third-party actions, least-privilege permissions, GITHUB_ENV/GITHUB_OUTPUT injection, secret exposure, OIDC over long-lived credentials, and self-hosted runner exposure on public repositories.

Compatibility and requirements

  • Use an agent runtime that supports Agent Skills and the linked SKILL.md format.
  • Confirm the source repository's tools, SDKs, and platform prerequisites for seo and content work.

How to install or import it

  • Open the linked GitHub SKILL.md and review its scope and setup instructions.
  • Install or import the skill using the agent runtime's documented workflow.
  • Run a small, non-sensitive test and verify the output before broader use.

Permissions and risks

  • Review every command, file path, network request, dependency, and credential scope before enabling it.
  • GitHub stars indicate popularity, not safety or correctness; validate the source and test with non-sensitive data.

Example workflows

  • Ask an AI agent to apply Github Actions Hardening to seo and content work described in the source record.
  • Have the agent state assumptions, required tools, and expected output before using this development & engineering skill.
  • Compare the result with the linked GitHub SKILL.md and verify it against your project requirements.

Related Agent Skills

More source records in Development & Engineering.

View category