Reviewdog
AgentSecOps/SecOpsAgentKit
Automated code review and security linting integration for CI/CD pipelines using reviewdog.
Security hardening reviewer for GitHub Actions workflow files (.github/workflows/.yml).
$ npx skills add github/awesome-copilot --skill github-actions-hardening -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install github/awesome-copilot github-actions-hardening --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/github/awesome-copilot.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/github-actions-hardening .claude/skills/github-actions-hardening && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "github-actions-hardening" agent skill from https://github.com/github/awesome-copilot/tree/main/skills/github-actions-hardening into .claude/skills/github-actions-hardening/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-actions-hardening", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/github/awesome-copilot/tree/main/skills/github-actions-hardeningType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add github/awesome-copilot --skill github-actions-hardening -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install github/awesome-copilot github-actions-hardening --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/awesome-copilot.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/github-actions-hardening .agents/skills/github-actions-hardening && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "github-actions-hardening" agent skill from https://github.com/github/awesome-copilot/tree/main/skills/github-actions-hardening into .agents/skills/github-actions-hardening/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-actions-hardening", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add github/awesome-copilot --skill github-actions-hardening -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install github/awesome-copilot github-actions-hardening --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/awesome-copilot.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/github-actions-hardening .cursor/skills/github-actions-hardening && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "github-actions-hardening" agent skill from https://github.com/github/awesome-copilot/tree/main/skills/github-actions-hardening into .cursor/skills/github-actions-hardening/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-actions-hardening", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/github/awesome-copilot.git --path skills/github-actions-hardening--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add github/awesome-copilot --skill github-actions-hardening -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install github/awesome-copilot github-actions-hardening --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/awesome-copilot.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/github-actions-hardening .gemini/skills/github-actions-hardening && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "github-actions-hardening" agent skill from https://github.com/github/awesome-copilot/tree/main/skills/github-actions-hardening into .gemini/skills/github-actions-hardening/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-actions-hardening", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install github/awesome-copilot github-actions-hardeningInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add github/awesome-copilot --skill github-actions-hardening -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/github/awesome-copilot.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/github-actions-hardening .github/skills/github-actions-hardening && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "github-actions-hardening" agent skill from https://github.com/github/awesome-copilot/tree/main/skills/github-actions-hardening into .github/skills/github-actions-hardening/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-actions-hardening", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add github/awesome-copilot --skill github-actions-hardening -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install github/awesome-copilot github-actions-hardening --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/awesome-copilot.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/github-actions-hardening .opencode/skills/github-actions-hardening && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "github-actions-hardening" agent skill from https://github.com/github/awesome-copilot/tree/main/skills/github-actions-hardening into .opencode/skills/github-actions-hardening/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-actions-hardening", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
github-actions-hardeningSecurity hardening reviewer for GitHub Actions workflow files (.github/workflows/.yml).
GitHub Actions Hardening is an agent skill from github/awesome-copilot, published by the product's own GitHub organization. Security hardening reviewer for GitHub Actions workflow files (.github/workflows/.yml). Reasons about the Actions threat model that pattern matchers and general code linters miss — untrusted-input script injection, privileged triggers running fork code, mutable action references, and over-scoped tokens. Use this skill when asked to review, audit, harden, or secure a GitHub Actions workflow, when writing a new workflow, or for any request like "is this workflow safe?", "review my CI for security issues", "why is…
Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `references/injection.md`, `references/permissions-and-tokens.md` and `references/report-format.md`).
It sits in DevOps & Cloud, covering CI/CD, Pull requests and Linting and formatting. It works with GitHub Actions and GitHub. The repository describes itself as: Community-contributed instructions, agents, skills, and configurations to help you make the most of GitHub Copilot. The licence is MIT.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 727ff2e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmbashFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
GITHUB_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
GitHub Actions Hardening loads about 2.4k tokens when it runs, and up to ~6k if it reads all its reference files. Until then it costs about 239 tokens; SKILL.md has 1,104 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from github/awesome-copilot at commit 727ff2e, republished under its MIT licence (© github). 1,104 words, ~2,449 tokens.
.claude/skills/github-actions-hardening/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.A focused security reviewer for GitHub Actions workflows. It reasons about the Actions-specific
threat model — where trust boundaries live in trigger types, token scopes, and string
interpolation — rather than the application-code vulnerabilities a general security scanner looks
for. Most workflow risks are invisible to language linters because the dangerous code is the YAML
itself and the way GitHub expands ${{ }} expressions into a shell before your script runs.
Use this skill when the request involves:
.github/workflows/pull_request_target, workflow_run, or issue_comment triggersGITHUB_TOKEN permissions or the permissions: keyrun: stepsIn a workflow, ${{ <expr> }} is expanded by the runner into the script before the shell
executes it. So a step like:
- run: echo "Title: ${{ github.event.issue.title }}"is not passing a variable — it is pasting attacker-controlled text directly into your shell
command. An issue titled "; <attacker-command> # is concatenated into the script and executed.
This single mechanism is the most common real-world Actions vulnerability, and models routinely
generate it. Treat every
${{ }} that contains data an outside contributor can influence as a code-injection sink.
Follow these steps in order for every workflow reviewed.
Read every on: trigger and classify the workflow's privilege:
push, pull_request (from same repo) → runs with the contributor's own trustpull_request from a fork → runs with a read-only token, no secrets (safe by design)pull_request_target, workflow_run, issue_comment, issues → run in the context of the
base repository with a read/write token and full access to secrets, but can be
triggered by outside contributors. These are the dangerous triggers.Read references/triggers-and-privilege.md for the full trust matrix.
For every run: block, every script: in actions/github-script, and every input to a custom
action, list the ${{ }} expressions and check whether any resolve to attacker-controllable data.
High-risk contexts include:
github.event.issue.title, github.event.issue.bodygithub.event.pull_request.title, github.event.pull_request.body, .head.ref, .head.labelgithub.event.comment.body, github.event.review.bodygithub.event.pages.*.page_name, github.event.commits.*.message, github.event.head_commit.*github.head_ref and any github.event.* field a fork author can setRead references/injection.md for the complete sink list and the safe-pattern fixes.
If a pull_request_target or workflow_run workflow checks out PR/fork code
(ref: ${{ github.event.pull_request.head.sha }}) and then runs it (build, test, install
scripts, npm install with lifecycle scripts, etc.), that is remote code execution against a
privileged token. Flag it as CRITICAL. The safe pattern is to split into two workflows: an
unprivileged pull_request workflow that runs the untrusted code, and a privileged
workflow_run workflow that only consumes its results.
permissions:permissions: block, the workflow inherits the repository default, which may
be read/write to everything. Flag it.permissions: {} (deny-all) or contents: read, then grant the minimum
per job (e.g. pull-requests: write only on the job that comments).permissions: write-all or broad write scopes that the steps don't actually need.Read references/permissions-and-tokens.md for the per-scope guidance and OIDC setup.
For every uses::
actions/* or github/*) MUST be pinned to a full 40-character
commit SHA, not a tag or branch. Tags and branches are mutable; a compromised upstream action
can rewrite v1 to malicious code that runs with your token and secrets.actions/* are lower risk but SHA-pinning is still the hardened recommendation.@main, @master, or any branch reference as HIGH — that is "latest" and can change under
you at any time.uses: foo/bar@<sha> # v2.1.0.Read references/supply-chain.md for pinning, Dependabot for actions, and artifact/cache risks.
set -x / bash -x in steps that touch
secrets.$GITHUB_ENV or $GITHUB_OUTPUT can inject environment
variables or step outputs — use the random-delimiter heredoc form and never write raw user input.actions/checkout leaves a token on disk by default; set persist-credentials: false when the
job later runs untrusted code.Output findings using the format in references/report-format.md: a severity summary table first,
then grouped findings with file, the exact offending YAML, the risk in plain English, and a
concrete before/after fix. Never auto-apply changes — present them for review.
| Severity | Meaning | Example |
|---|---|---|
| 🔴 CRITICAL | Token/secret theft or RCE reachable by an outside contributor | pull_request_target checking out and running fork code; ${{ github.event.* }} in a run: on a privileged trigger |
| 🟠 HIGH | Exploitable supply-chain or scope problem | Third-party action on a mutable tag/branch; write-all permissions; injection sink on issue_comment |
| 🟡 MEDIUM | Risk under conditions or chaining | Missing permissions: block; secret reachable by a non-fork PR author |
| 🔵 LOW | Hardening gap, low direct risk | First-party action not SHA-pinned; persist-credentials left default on a non-privileged job |
| ⚪ INFO | Observation, not a vulnerability | Version comment missing next to a pinned SHA |
pull_request is dangerous just because it runs untrusted code — it has
no secrets and a read-only token. Reserve CRITICAL for the privileged triggers.Load these as needed:
references/triggers-and-privilege.md — Trust matrix for every trigger, why pull_request_target
and workflow_run are privileged, and the two-workflow safe pattern.pull_request_target, workflow_run, issue_comment, fork, secrets, read-only token, trust boundaryreferences/injection.md — Full list of attacker-controllable ${{ }} contexts and the
env:-variable safe pattern for each sink (run, github-script, action inputs).script injection, github.event, head_ref, issue title, env, intermediate variable, actions/github-scriptreferences/permissions-and-tokens.md — GITHUB_TOKEN scopes, least-privilege permissions:
recipes per job type, and OIDC for cloud auth instead of long-lived secrets.permissions, GITHUB_TOKEN, write-all, contents: read, id-token, OIDC, least privilegereferences/supply-chain.md — SHA-pinning third-party actions, Dependabot for github-actions,
artifact and cache poisoning across workflow_run, and self-hosted runner exposure.SHA pin, uses, mutable tag, Dependabot, download-artifact, cache, self-hosted runnerreferences/report-format.md — Output template: summary table, finding cards, and before/after
remediation blocks.report, format, finding, summary, remediation, before, after© github, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 5 other files (references) in skills/github-actions-hardening of github/awesome-copilot.
Open the folder on GitHubat commit 727ff2e
We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in github/awesome-copilot, which our catalogue first saw on October 7, 2026.
GitHub Actions Hardening next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| GitHub Actions Hardening this skillgithub/awesome-copilot | 40k | 1 repos | ~2.4k | Automated safety check: Pass | MIT | |
| ReviewdogAgentSecOps/SecOpsAgentKit | 219 | 1 repos | ~3k | Automated safety check: Pass | Custom licence | |
| Qv Devops PR Reviewtetherto/qvac | 674 | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | |
| Secure GitHub Actionsvechain/x-app-template | 450 | — | ~1.2k | Automated safety check: Pass | MIT | |
| CIaiblueprinthq/ai-blueprint | 458 | — | ~2.2k | Automated safety check: Pass | MIT | |
| Securing GitHub Actions Workflowsmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 |
AgentSecOps/SecOpsAgentKit
Automated code review and security linting integration for CI/CD pipelines using reviewdog.
tetherto/qvac
PR review for DevOps changes — runs the generic /qv-pr-review flow then layers a structured GitHub Actions security audit (action pinning, permissions, OIDC, secrets handling).
vechain/x-app-template
Secure GitHub Actions workflows against supply-chain, privilege, and shell-injection risks.
aiblueprinthq/ai-blueprint
Set up or normalize one project Verify command and matching GitHub Actions checks while preserving existing CI, with an optional local pre-push hook.
mukul975/Anthropic-Cybersecurity-Skills
Hardens GitHub Actions workflows against supply chain attacks, credential theft, and privilege escalation: pinning actions to SHA digests, minimizing GITHUBTOKEN permissions, protecting secrets…
PackmindHub/packmind
Diagnose a failed, stuck, or never-triggered CI run on a GitHub PR, apply a local fix if possible, push it, and document the result in a single running PR comment.
github/awesome-copilot
Maps an unfamiliar codebase into seven evidence-backed documents in docs/codebase/, using a scan script and templates, for onboarding or architecture write-ups.
github/awesome-copilot
Designs Azure infrastructure from a natural-language description, or diagrams an existing resource group, then refines the design through conversation and deploys it with Bicep.
github/awesome-copilot
Generates, edits and validates draw.io files with correct mxGraph XML, covering flowcharts, architecture, sequence, ER and UML class diagrams.
github/awesome-copilot
Cleans raw credit data and screens variables before loan modeling, dropping unstable, noisy or redundant features and writing an Excel report of every step.
github/awesome-copilot
Builds a warm, browser-based daily focus board the user updates by talking to their agent, with Eisenhower priorities, a brain-dump box and kind not-today carryover.
github/awesome-copilot
End-to-end skill for building, testing, linting, versioning, and publishing a production-grade Python library to PyPI.
Works with
Categories
Security hardening reviewer for GitHub Actions workflow files (.github/workflows/.yml). GitHub Actions Hardening is an agent skill from github/awesome-copilot, published by the product's own GitHub organization.yml).
GitHub Actions Hardening fits situations like: running fork code; mutable action references; over-scoped tokens; asked to review.
Run `npx skills add github/awesome-copilot --skill github-actions-hardening -a claude-code`. Or copy the skill folder (skills/github-actions-hardening in github/awesome-copilot) into .claude/skills/github-actions-hardening in your project. Claude Code loads it when a task matches its description.
Run `npx skills add github/awesome-copilot --skill github-actions-hardening -a codex`. Or copy the skill folder (skills/github-actions-hardening in github/awesome-copilot) into .agents/skills/github-actions-hardening in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add github/awesome-copilot --skill github-actions-hardening -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/github-actions-hardening, .gemini/skills/github-actions-hardening, .github/skills/github-actions-hardening and .opencode/skills/github-actions-hardening in your project.
Going by SKILL.md and its folder, GitHub Actions Hardening needs the command-line tools its instructions call (npm and bash) and credentials named GITHUB_TOKEN. Our summary lists: Node.js; A credential in GITHUB_TOKEN.
SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
GitHub Actions Hardening is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.5k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with GitHub Actions Hardening: Reviewdog (AgentSecOps/SecOpsAgentKit, 219 stars), Qv Devops PR Review (tetherto/qvac, 674 stars), Secure GitHub Actions (vechain/x-app-template, 450 stars) and CI (aiblueprinthq/ai-blueprint, 458 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
github (a GitHub organization, an official publisher) maintains it in github/awesome-copilot, which has 39,748 GitHub stars. The repository holds 417 skills in this directory. The repository was last updated on October 7, 2026.
Source: github/awesome-copilot on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.