Official agent skill

GitHub Actions Hardening

by github in github/awesome-copilot

Security hardening reviewer for GitHub Actions workflow files (.github/workflows/.yml).

OfficialMITAuto-check passedDevOps & Cloud

Install GitHub Actions Hardening

skills CLI
$ npx skills add github/awesome-copilot --skill github-actions-hardening -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install github/awesome-copilot github-actions-hardening --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/github/awesome-copilot.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/github-actions-hardening .claude/skills/github-actions-hardening && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
github-actions-hardening
GitHub stars
40k
Used in
1 other repo
Token cost
~2.4k tokens
SKILL.md length
1,104 words
Files
6 (incl. references)
Skills in repo
417
Repo updated
First seen
Licence
MIT

At a glance

Security hardening reviewer for GitHub Actions workflow files (.github/workflows/.yml).

  • Works in 7 steps: Map the Triggers and Trust Level → Hunt for Script Injection → Check Privileged Triggers Don't Execute… → …
  • Running fork code
  • SKILL.md covers When to Use This Skill, The Core Insight, Execution Workflow and Severity Guide, plus 2 more sections
  • Calls npm and bash; needs GITHUB_TOKEN

What it does

GitHub Actions Hardening is an agent skill from github/awesome-copilot, published by the product's own GitHub organization. Security hardening reviewer for GitHub Actions workflow files (.github/workflows/.yml). Reasons about the Actions threat model that pattern matchers and general code linters miss — untrusted-input script injection, privileged triggers running fork code, mutable action references, and over-scoped tokens. Use this skill when asked to review, audit, harden, or secure a GitHub Actions workflow, when writing a new workflow, or for any request like "is this workflow safe?", "review my CI for security issues", "why is…

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `references/injection.md`, `references/permissions-and-tokens.md` and `references/report-format.md`).

It sits in DevOps & Cloud, covering CI/CD, Pull requests and Linting and formatting. It works with GitHub Actions and GitHub. The repository describes itself as: Community-contributed instructions, agents, skills, and configurations to help you make the most of GitHub Copilot. The licence is MIT.

When your agent uses it

  • Running fork code
  • Mutable action references
  • Over-scoped tokens
  • Asked to review

Example prompts

  • “is this workflow safe?”
  • “review my CI for security issues”
  • “why is pullrequesttarget dangerous here?”
  • “/github-actions-hardening”

Requirements

  • Node.js
  • A credential in GITHUB_TOKEN

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Map the Triggers and Trust Level
  2. Hunt for Script Injection
  3. Check Privileged Triggers Don't Execute Untrusted Code
  4. Audit permissions
  5. Audit Action References (Supply Chain)
  6. Check Secret and Output Handling
  7. Produce the Report

What it can do on your machine

Read from SKILL.md and the folder at commit 727ff2e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GITHUB_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

GitHub Actions Hardening loads about 2.4k tokens when it runs, and up to ~6k if it reads all its reference files. Until then it costs about 239 tokens; SKILL.md has 1,104 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~239
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from github/awesome-copilot at commit 727ff2e, republished under its MIT licence (© github). 1,104 words, ~2,449 tokens.

Download SKILL.mdSave it as .claude/skills/github-actions-hardening/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
github-actions-hardening
description
Security hardening reviewer for GitHub Actions workflow files (.github/workflows/*.yml). Reasons about the Actions threat model that pattern matchers and general code linters miss — untrusted-input script injection, privileged triggers running fork code, mutable action references, and over-scoped tokens. Use this skill when asked to review, audit, harden, or secure a GitHub Actions workflow, when writing a new workflow, or for any request like "is this workflow safe?", "review my CI for security issues", "why is pull_request_target dangerous here?", "pin my actions", or "lock down GITHUB_TOKEN permissions". Covers script injection via ${{ }} interpolation, pull_request_target / workflow_run privilege escalation, SHA-pinning of third-party actions, least-privilege permissions, GITHUB_ENV/GITHUB_OUTPUT injection, secret exposure, OIDC over long-lived credentials, and self-hosted runner exposure on public repositories.

GitHub Actions Hardening

A focused security reviewer for GitHub Actions workflows. It reasons about the Actions-specific threat model — where trust boundaries live in trigger types, token scopes, and string interpolation — rather than the application-code vulnerabilities a general security scanner looks for. Most workflow risks are invisible to language linters because the dangerous code is the YAML itself and the way GitHub expands ${{ }} expressions into a shell before your script runs.

When to Use This Skill

Use this skill when the request involves:

  • Reviewing, auditing, or hardening any file under .github/workflows/
  • Authoring a new workflow and wanting it secure by default
  • A workflow that uses pull_request_target, workflow_run, or issue_comment triggers
  • Questions about GITHUB_TOKEN permissions or the permissions: key
  • Pinning actions to commit SHAs vs tags vs branches
  • Handling untrusted input (issue titles, PR bodies, branch names, commit messages) in run: steps
  • OIDC / cloud authentication from Actions, or secret handling in CI
  • Self-hosted runners on public repositories
  • Any request like "is this workflow safe?", "secure my CI", or "review this GitHub Action"

The Core Insight

In a workflow, ${{ <expr> }} is expanded by the runner into the script before the shell executes it. So a step like:

yaml
- run: echo "Title: ${{ github.event.issue.title }}"

is not passing a variable — it is pasting attacker-controlled text directly into your shell command. An issue titled "; <attacker-command> # is concatenated into the script and executed. This single mechanism is the most common real-world Actions vulnerability, and models routinely generate it. Treat every ${{ }} that contains data an outside contributor can influence as a code-injection sink.

Execution Workflow

Follow these steps in order for every workflow reviewed.

Step 1 — Map the Triggers and Trust Level

Read every on: trigger and classify the workflow's privilege:

  • push, pull_request (from same repo) → runs with the contributor's own trust
  • pull_request from a fork → runs with a read-only token, no secrets (safe by design)
  • pull_request_target, workflow_run, issue_comment, issues → run in the context of the base repository with a read/write token and full access to secrets, but can be triggered by outside contributors. These are the dangerous triggers.

Read references/triggers-and-privilege.md for the full trust matrix.

Step 2 — Hunt for Script Injection

For every run: block, every script: in actions/github-script, and every input to a custom action, list the ${{ }} expressions and check whether any resolve to attacker-controllable data. High-risk contexts include:

  • github.event.issue.title, github.event.issue.body
  • github.event.pull_request.title, github.event.pull_request.body, .head.ref, .head.label
  • github.event.comment.body, github.event.review.body
  • github.event.pages.*.page_name, github.event.commits.*.message, github.event.head_commit.*
  • github.head_ref and any github.event.* field a fork author can set

Read references/injection.md for the complete sink list and the safe-pattern fixes.

Step 3 — Check Privileged Triggers Don't Execute Untrusted Code

If a pull_request_target or workflow_run workflow checks out PR/fork code (ref: ${{ github.event.pull_request.head.sha }}) and then runs it (build, test, install scripts, npm install with lifecycle scripts, etc.), that is remote code execution against a privileged token. Flag it as CRITICAL. The safe pattern is to split into two workflows: an unprivileged pull_request workflow that runs the untrusted code, and a privileged workflow_run workflow that only consumes its results.

Step 4 — Audit permissions:
  • If there is no permissions: block, the workflow inherits the repository default, which may be read/write to everything. Flag it.
  • Recommend a top-level permissions: {} (deny-all) or contents: read, then grant the minimum per job (e.g. pull-requests: write only on the job that comments).
  • Flag any permissions: write-all or broad write scopes that the steps don't actually need.

Read references/permissions-and-tokens.md for the per-scope guidance and OIDC setup.

Step 5 — Audit Action References (Supply Chain)

For every uses::

  • Third-party actions (not actions/* or github/*) MUST be pinned to a full 40-character commit SHA, not a tag or branch. Tags and branches are mutable; a compromised upstream action can rewrite v1 to malicious code that runs with your token and secrets.
  • First-party actions/* are lower risk but SHA-pinning is still the hardened recommendation.
  • Flag @main, @master, or any branch reference as HIGH — that is "latest" and can change under you at any time.
  • Note the human-readable version in a trailing comment: uses: foo/bar@<sha> # v2.1.0.

Read references/supply-chain.md for pinning, Dependabot for actions, and artifact/cache risks.

Show full SKILL.md (444 more words)Show less
Step 6 — Check Secret and Output Handling
  • No secrets echoed, printed, or written to logs; no set -x / bash -x in steps that touch secrets.
  • Secrets must not be passed to steps that run untrusted code or to untrusted third-party actions.
  • Untrusted multiline data written to $GITHUB_ENV or $GITHUB_OUTPUT can inject environment variables or step outputs — use the random-delimiter heredoc form and never write raw user input.
  • actions/checkout leaves a token on disk by default; set persist-credentials: false when the job later runs untrusted code.
Step 7 — Produce the Report

Output findings using the format in references/report-format.md: a severity summary table first, then grouped findings with file, the exact offending YAML, the risk in plain English, and a concrete before/after fix. Never auto-apply changes — present them for review.

Severity Guide

SeverityMeaningExample
🔴 CRITICALToken/secret theft or RCE reachable by an outside contributorpull_request_target checking out and running fork code; ${{ github.event.* }} in a run: on a privileged trigger
🟠 HIGHExploitable supply-chain or scope problemThird-party action on a mutable tag/branch; write-all permissions; injection sink on issue_comment
🟡 MEDIUMRisk under conditions or chainingMissing permissions: block; secret reachable by a non-fork PR author
🔵 LOWHardening gap, low direct riskFirst-party action not SHA-pinned; persist-credentials left default on a non-privileged job
⚪ INFOObservation, not a vulnerabilityVersion comment missing next to a pinned SHA

Output Rules

  • Always show a findings summary table (counts by severity) first.
  • Group by issue type, not by file.
  • Be exact — quote the offending line and give the line location.
  • Always pair every CRITICAL/HIGH with a concrete corrected YAML snippet.
  • Never claim a fork pull_request is dangerous just because it runs untrusted code — it has no secrets and a read-only token. Reserve CRITICAL for the privileged triggers.
  • If the workflow is already hardened, say so and list what was checked.

Reference Files

Load these as needed:

  • references/triggers-and-privilege.md — Trust matrix for every trigger, why pull_request_target and workflow_run are privileged, and the two-workflow safe pattern.
    • Search patterns: pull_request_target, workflow_run, issue_comment, fork, secrets, read-only token, trust boundary
  • references/injection.md — Full list of attacker-controllable ${{ }} contexts and the env:-variable safe pattern for each sink (run, github-script, action inputs).
    • Search patterns: script injection, github.event, head_ref, issue title, env, intermediate variable, actions/github-script
  • references/permissions-and-tokens.md — GITHUB_TOKEN scopes, least-privilege permissions: recipes per job type, and OIDC for cloud auth instead of long-lived secrets.
    • Search patterns: permissions, GITHUB_TOKEN, write-all, contents: read, id-token, OIDC, least privilege
  • references/supply-chain.md — SHA-pinning third-party actions, Dependabot for github-actions, artifact and cache poisoning across workflow_run, and self-hosted runner exposure.
    • Search patterns: SHA pin, uses, mutable tag, Dependabot, download-artifact, cache, self-hosted runner
  • references/report-format.md — Output template: summary table, finding cards, and before/after remediation blocks.
    • Search patterns: report, format, finding, summary, remediation, before, after

© github, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (references) in skills/github-actions-hardening of github/awesome-copilot.

  • SKILL.md
  • references/injection.md
  • references/permissions-and-tokens.md
  • references/report-format.md
  • references/supply-chain.md
  • references/triggers-and-privilege.md

Open the folder on GitHubat commit 727ff2e

Used in 1 other repository

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in github/awesome-copilot, which our catalogue first saw on October 7, 2026.

Compare with similar skills

GitHub Actions Hardening next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

GitHub Actions Hardening compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
GitHub Actions Hardening this skillgithub/awesome-copilot40k1 repos~2.4kAutomated safety check: PassMIT
ReviewdogAgentSecOps/SecOpsAgentKit2191 repos~3kAutomated safety check: PassCustom licence
Qv Devops PR Reviewtetherto/qvac674—~2.5kAutomated safety check: PassApache-2.0
Secure GitHub Actionsvechain/x-app-template450—~1.2kAutomated safety check: PassMIT
CIaiblueprinthq/ai-blueprint458—~2.2kAutomated safety check: PassMIT
Securing GitHub Actions Workflowsmukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.0

Similar skills

  • Reviewdog

    AgentSecOps/SecOpsAgentKit

    Automated code review and security linting integration for CI/CD pipelines using reviewdog.

    219 GitHub starsUsed in 1 repo~3k tokens
    DevelopmentAuto-check passed
  • Qv Devops PR Review

    tetherto/qvac

    PR review for DevOps changes — runs the generic /qv-pr-review flow then layers a structured GitHub Actions security audit (action pinning, permissions, OIDC, secrets handling).

    674 GitHub stars~2.5k tokensUpdated today
    DevelopmentAuto-check passed
  • Secure GitHub Actions

    vechain/x-app-template

    Secure GitHub Actions workflows against supply-chain, privilege, and shell-injection risks.

    450 GitHub stars~1.2k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • CI

    aiblueprinthq/ai-blueprint

    Set up or normalize one project Verify command and matching GitHub Actions checks while preserving existing CI, with an optional local pre-push hook.

    458 GitHub stars~2.2k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Securing GitHub Actions Workflows

    mukul975/Anthropic-Cybersecurity-Skills

    Hardens GitHub Actions workflows against supply chain attacks, credential theft, and privilege escalation: pinning actions to SHA digests, minimizing GITHUBTOKEN permissions, protecting secrets…

    34k GitHub stars~2.2k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Diagnose a failed, stuck, or never-triggered CI run on a GitHub PR, apply a local fix if possible, push it, and document the result in a single running PR comment.

    317 GitHub stars~2.6k tokensUpdated today
    DevOps & CloudAuto-check passed

More from github/awesome-copilot

All 417 skills in this repo
  • Acquire Codebase Knowledge

    github/awesome-copilot

    Official

    Maps an unfamiliar codebase into seven evidence-backed documents in docs/codebase/, using a scan script and templates, for onboarding or architecture write-ups.

    40k GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Azure Architecture Autopilot

    github/awesome-copilot

    Official

    Designs Azure infrastructure from a natural-language description, or diagrams an existing resource group, then refines the design through conversation and deploys it with Bicep.

    40k GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check passed
  • Draw.io Diagram Generator

    github/awesome-copilot

    Official

    Generates, edits and validates draw.io files with correct mxGraph XML, covering flowcharts, architecture, sequence, ER and UML class diagrams.

    40k GitHub starsUsed in 1 repo~4.9k tokens
    Auto-check passed
  • Credit Risk Data Cleaning

    github/awesome-copilot

    Official

    Cleans raw credit data and screens variables before loan modeling, dropping unstable, noisy or redundant features and writing an Excel report of every step.

    40k GitHub starsUsed in 1 repo~1.5k tokens
    Auto-check passed
  • Daily Focus Board

    github/awesome-copilot

    Official

    Builds a warm, browser-based daily focus board the user updates by talking to their agent, with Eisenhower priorities, a brain-dump box and kind not-today carryover.

    40k GitHub stars~3k tokensUpdated today
    Auto-check passed
  • Python Pypi Package Builder

    github/awesome-copilot

    Official

    End-to-end skill for building, testing, linting, versioning, and publishing a production-grade Python library to PyPI.

    40k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Questions about GitHub Actions Hardening

What does GitHub Actions Hardening do?

Security hardening reviewer for GitHub Actions workflow files (.github/workflows/.yml). GitHub Actions Hardening is an agent skill from github/awesome-copilot, published by the product's own GitHub organization.yml).

When should I use GitHub Actions Hardening?

GitHub Actions Hardening fits situations like: running fork code; mutable action references; over-scoped tokens; asked to review.

How do I install GitHub Actions Hardening in Claude Code?

Run `npx skills add github/awesome-copilot --skill github-actions-hardening -a claude-code`. Or copy the skill folder (skills/github-actions-hardening in github/awesome-copilot) into .claude/skills/github-actions-hardening in your project. Claude Code loads it when a task matches its description.

How do I install GitHub Actions Hardening in Codex?

Run `npx skills add github/awesome-copilot --skill github-actions-hardening -a codex`. Or copy the skill folder (skills/github-actions-hardening in github/awesome-copilot) into .agents/skills/github-actions-hardening in your project. Codex loads it when a task matches its description.

Can I use GitHub Actions Hardening in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add github/awesome-copilot --skill github-actions-hardening -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/github-actions-hardening, .gemini/skills/github-actions-hardening, .github/skills/github-actions-hardening and .opencode/skills/github-actions-hardening in your project.

What does GitHub Actions Hardening need to run?

Going by SKILL.md and its folder, GitHub Actions Hardening needs the command-line tools its instructions call (npm and bash) and credentials named GITHUB_TOKEN. Our summary lists: Node.js; A credential in GITHUB_TOKEN.

Does GitHub Actions Hardening access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is GitHub Actions Hardening safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does GitHub Actions Hardening use?

GitHub Actions Hardening is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does GitHub Actions Hardening use?

About 2.4k tokens (SKILL.md is roughly 9.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.5k tokens, read only when the agent opens those files.

What are the alternatives to GitHub Actions Hardening?

Skills that share tags, products or a category with GitHub Actions Hardening: Reviewdog (AgentSecOps/SecOpsAgentKit, 219 stars), Qv Devops PR Review (tetherto/qvac, 674 stars), Secure GitHub Actions (vechain/x-app-template, 450 stars) and CI (aiblueprinthq/ai-blueprint, 458 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains GitHub Actions Hardening?

github (a GitHub organization, an official publisher) maintains it in github/awesome-copilot, which has 39,748 GitHub stars. The repository holds 417 skills in this directory. The repository was last updated on October 7, 2026.

Source: github/awesome-copilot on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.