Secure GitHub Actions
vechain/x-app-template
Secure GitHub Actions workflows against supply-chain, privilege, and shell-injection risks.
Create secure CI/CD workflows with GitHub Actions for Java 26/Maven/PostgreSQL builds, security scans, and deployments
$ npx skills add Hack23/cia --skill github-actions-workflows -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Hack23/cia github-actions-workflows --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/github-actions-workflows .claude/skills/github-actions-workflows && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "github-actions-workflows" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/github-actions-workflows into .claude/skills/github-actions-workflows/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-actions-workflows", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Hack23/cia/tree/master/.github/skills/github-actions-workflowsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Hack23/cia --skill github-actions-workflows -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Hack23/cia github-actions-workflows --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.github/skills/github-actions-workflows .agents/skills/github-actions-workflows && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "github-actions-workflows" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/github-actions-workflows into .agents/skills/github-actions-workflows/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-actions-workflows", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Hack23/cia --skill github-actions-workflows -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Hack23/cia github-actions-workflows --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.github/skills/github-actions-workflows .cursor/skills/github-actions-workflows && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "github-actions-workflows" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/github-actions-workflows into .cursor/skills/github-actions-workflows/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-actions-workflows", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Hack23/cia.git --path .github/skills/github-actions-workflows--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Hack23/cia --skill github-actions-workflows -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Hack23/cia github-actions-workflows --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.github/skills/github-actions-workflows .gemini/skills/github-actions-workflows && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "github-actions-workflows" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/github-actions-workflows into .gemini/skills/github-actions-workflows/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-actions-workflows", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Hack23/cia github-actions-workflowsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Hack23/cia --skill github-actions-workflows -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .github/skills && cp -r skills-src/.github/skills/github-actions-workflows .github/skills/github-actions-workflows && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "github-actions-workflows" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/github-actions-workflows into .github/skills/github-actions-workflows/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-actions-workflows", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Hack23/cia --skill github-actions-workflows -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Hack23/cia github-actions-workflows --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.github/skills/github-actions-workflows .opencode/skills/github-actions-workflows && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "github-actions-workflows" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/github-actions-workflows into .opencode/skills/github-actions-workflows/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-actions-workflows", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
github-actions-workflowsCreate secure CI/CD workflows with GitHub Actions for Java 26/Maven/PostgreSQL builds, security scans, and deployments
GitHub Actions Workflows is an agent skill from Hack23/cia. Create secure CI/CD workflows with GitHub Actions for Java 26/Maven/PostgreSQL builds, security scans, and deployments
Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering CI/CD and Security review. It works with GitHub Actions, PostgreSQL and Java. The repository describes itself as: Citizen Intelligence Agency. Open-source intelligence platform analyzing Swedish political activities using AI and data visualization. Tracks politicians, government… The licence is Apache-2.0.
Read from SKILL.md and the folder at commit 6a9797b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml).
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
docs.github.comslsa.devsecurityscorecards.devFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
SONAR_TOKENPOSTGRES_PASSWORDDB_PASSWORDFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
GitHub Actions Workflows loads about 1.9k tokens when it runs. Until then it costs about 36 tokens; SKILL.md has 341 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Hack23/cia at commit 6a9797b, republished under its Apache-2.0 licence (© Hack23). 341 words, ~1,942 tokens.
.claude/skills/github-actions-workflows/SKILL.md (or your agent's skills folder).Create and maintain secure, efficient CI/CD pipelines using GitHub Actions for the CIA platform. Covers build, test, security scanning, deployment, and agentic workflow integration.
gh-aw)| Component | Version | Notes |
|---|---|---|
| Java JDK | 26 (Temurin) | Source level 21 |
| Maven | 3.9.15 | Multi-module reactor build |
| PostgreSQL | 18 | Extensions: pgaudit, pgcrypto, pg_stat_statements |
| Node.js | 24 | MCP servers, Playwright |
| Runner | ubuntu-latest | GitHub Actions hosted |
name: CI/CD Pipeline
on:
push:
branches: [master]
pull_request:
branches: [master]
permissions:
contents: read
security-events: write
actions: read
jobs:
build:
permissions:
contents: read
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- name: Set up JDK 26
uses: actions/setup-java@c5195efecf7bdfc987ee8bae7a71cb8b11521c00 # v4.7.1
with:
java-version: '26'
distribution: 'temurin'
cache: 'maven'
- name: Build with Maven
run: mvn clean install -DskipTests
- name: Run Tests
run: mvn test -Dtest='!**ITest*,!**/XmlDateTypeAdapterTest,!**/XmlTimeTypeAdapterTest,!**/XmlDateTimeTypeAdapterTest'
- name: Upload Coverage
uses: codecov/codecov-action@18283e04ce6e62d37312384ff67231eb8fd56d24 # v5.4.3
with:
files: '**/target/site/jacoco/jacoco.xml'
security:
runs-on: ubuntu-latest
needs: build
steps:
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- name: Initialize CodeQL
uses: github/codeql-action/init@ff0a06e83cb2de871e5a09832bc6a81e7276941f # v3.28.18
with:
languages: java
- name: Autobuild
uses: github/codeql-action/autobuild@ff0a06e83cb2de871e5a09832bc6a81e7276941f # v3.28.18
# Note: The actual codeql-analysis.yml uses a custom Maven build instead of autobuild.
# Replace this step with a manual build if autobuild fails for your project.
- name: CodeQL Analysis
uses: github/codeql-action/analyze@ff0a06e83cb2de871e5a09832bc6a81e7276941f # v3.28.18
- name: OWASP Dependency Check
run: mvn org.owasp:dependency-check-maven:check
deploy:
runs-on: ubuntu-latest
needs: [build, security]
if: github.ref == 'refs/heads/master'
permissions:
id-token: write # Required for OIDC
contents: read
steps:
- name: Deploy to AWS
uses: aws-actions/configure-aws-credentials@ececac1a45f3b08a01d2dd070d28d111c5fe6722 # v4.1.0
with:
role-to-assume: ${{ secrets.AWS_ROLE_ARN }}
aws-region: eu-north-1Always pin actions to full SHA commit hashes, never tags:
# ✅ Correct - pinned to SHA
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
# ❌ Wrong - mutable tag
- uses: actions/checkout@v4Always declare minimal permissions at workflow and job level:
permissions:
contents: read # Default for most jobs
security-events: write # Only for security scan uploads
issues: write # Only for issue management jobs# ✅ Use GitHub secrets
env:
SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
# ✅ Use OIDC for cloud access (no long-lived keys)
- uses: aws-actions/configure-aws-credentials@ececac1a45f3b08a01d2dd070d28d111c5fe6722 # v4.1.0
with:
role-to-assume: ${{ secrets.AWS_ROLE_ARN }}
# ❌ Never hardcode credentials# SLSA 3 build provenance (pin to a specific commit SHA)
- uses: slsa-framework/slsa-github-generator/.github/workflows/builder_maven.yml@3c58c41cab36161dc53f223132d1f59f1df67cf9 # v2
with:
rekor-log-public: true| Workflow | Purpose | Trigger |
|---|---|---|
codeql-analysis.yml | Security vulnerability scanning | Push/PR to master + scheduled |
dependency-review.yml | Dependency security checks | PR only |
scorecards.yml | OpenSSF Scorecard assessment | Scheduled |
release.yml | Build artifacts + SLSA attestations | Manual (workflow_dispatch) |
copilot-setup-steps.yml | Copilot agent build environment | Copilot sessions |
javadoc-generation.yml | JavaDoc generation | Push/scheduled |
site-generation.yml | Maven site generation | Push/scheduled |
zap-scan.yml | OWASP ZAP security scan | Scheduled |
generate-intelligence-changelog.yml | Intelligence changelog generation | Manual (workflow_dispatch) |
labeler.yml | Pull request auto-labeling | pull_request_target |
validate-field-completeness.yml | JSON export field completeness | Push (path-filtered) |
validate-json-schemas.yml | JSON schema validation | Push/PR (path-filtered) + scheduled |
validate-view-documentation.yml | View documentation validation | Scheduled (monthly) + PR (path-filtered) |
services:
postgres:
image: postgres:18
env:
POSTGRES_USER: eris
POSTGRES_PASSWORD: ${{ secrets.DB_PASSWORD }}
POSTGRES_DB: cia_dev
options: >-
--health-cmd pg_isready
--health-interval 10s
--health-timeout 5s
--health-retries 5
ports:
- 5432:5432# Multi-level caching for resilience
- name: Cache Maven repository
uses: actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5.0.4
with:
path: ~/.m2/repository
key: ${{ runner.os }}-maven-${{ hashFiles('**/pom.xml') }}
restore-keys: |
${{ runner.os }}-maven-
# Parallel builds for multi-module projects
- name: Build
run: mvn -T 1C clean install -DskipTestsGitHub Agentic Workflows (gh-aw) complement traditional Actions:
| Aspect | Traditional Actions | Agentic Workflows |
|---|---|---|
| Logic | Deterministic YAML | Natural language AI |
| Decisions | Pre-programmed conditionals | Context-aware reasoning |
| Format | .yml files | .md files → compiled to .lock.yml |
| Security | Manual permission management | Built-in 5-layer security |
| Best for | Build, test, deploy | Triage, review, docs, analysis |
Use both together: traditional Actions for deterministic build/test/deploy, agentic workflows for intelligent automation.
| Control | Implementation |
|---|---|
| ISO 27001 A.8.8 | Change management via PR-gated workflow changes |
| ISO 27001 A.8.15 | Audit logging via Actions run logs |
| NIST CSF PR.IP-1 | Baseline configuration via pinned action versions |
| CIS Control 16 | Application security via CodeQL + OWASP in pipeline |
.github/workflows/© Hack23, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .github/skills/github-actions-workflows of Hack23/cia.
Open the folder on GitHubat commit 6a9797b
GitHub Actions Workflows next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| GitHub Actions Workflows this skillHack23/cia | 239 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | |
| Secure GitHub Actionsvechain/x-app-template | 450 | — | ~1.2k | Automated safety check: Pass | MIT | |
| Code PatternsAedelon/claude-code-blueprint | 120 | — | ~1.2k | Automated safety check: Pass | Custom licence | |
| Cicd Pipelinerevfactory/harness-100 | 1.3k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | |
| Agentic GitHub Actions Auditortrailofbits/skills | 7.4k | 6 repos | ~5.4k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| GitHub Actions Hardeninggithub/awesome-copilot | 40k | 1 repos | ~2.4k | Automated safety check: Pass | MIT |
vechain/x-app-template
Secure GitHub Actions workflows against supply-chain, privilege, and shell-injection risks.
Aedelon/claude-code-blueprint
Reference patterns for REST APIs, pytest/vitest testing, Docker multi-stage builds, GitHub Actions CI/CD, PostgreSQL, TypeScript generics, Python async, and React Server Components.
revfactory/harness-100
Full pipeline for CI/CD pipeline design, build, monitoring, and optimization.
trailofbits/skills
Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.
github/awesome-copilot
Security hardening reviewer for GitHub Actions workflow files (.github/workflows/.yml).
rileyhilliard/claude-essentials
Guides GitHub Actions CI/CD architecture, security hardening, and deployment strategies.
Hack23/cia
WCAG 2.1 AA compliance, ARIA attributes, keyboard navigation, screen reader optimization for accessible political data platforms
Hack23/cia
Advanced chart types, D3.js/Vaadin Charts patterns, political data visualization, time series analysis
Hack23/cia
AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents
Hack23/cia
External API integration patterns, retry logic, circuit breakers, caching, rate limiting for government data APIs
Hack23/cia
AWS CloudWatch metrics, alarms, dashboards, log insights, and application monitoring for the CIA platform
Hack23/cia
AWS security best practices, VPC security, IAM, KMS, CloudTrail, GuardDuty for CIA platform deployment
Works with
Categories
Create secure CI/CD workflows with GitHub Actions for Java 26/Maven/PostgreSQL builds, security scans, and deployments. GitHub Actions Workflows is an agent skill from Hack23/cia.
GitHub Actions Workflows fits situations like: tasks that involve CI/CD; tasks that involve Security review.
Run `npx skills add Hack23/cia --skill github-actions-workflows -a claude-code`. Or copy the skill folder (.github/skills/github-actions-workflows in Hack23/cia) into .claude/skills/github-actions-workflows in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Hack23/cia --skill github-actions-workflows -a codex`. Or copy the skill folder (.github/skills/github-actions-workflows in Hack23/cia) into .agents/skills/github-actions-workflows in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Hack23/cia --skill github-actions-workflows -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/github-actions-workflows, .gemini/skills/github-actions-workflows, .github/skills/github-actions-workflows and .opencode/skills/github-actions-workflows in your project.
Going by SKILL.md and its folder, GitHub Actions Workflows needs credentials named SONAR_TOKEN, POSTGRES_PASSWORD and DB_PASSWORD. Our summary lists: Node.js; A credential in SONAR_TOKEN.
SKILL.md names 3 domains. As links in the text: docs.github.com, slsa.dev and securityscorecards.dev. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
GitHub Actions Workflows is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.9k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with GitHub Actions Workflows: Secure GitHub Actions (vechain/x-app-template, 450 stars), Code Patterns (Aedelon/claude-code-blueprint, 120 stars), Cicd Pipeline (revfactory/harness-100, 1.3k stars) and Agentic GitHub Actions Auditor (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Hack23 (a GitHub organization) maintains it in Hack23/cia, which has 239 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 6, 2026.
Source: Hack23/cia on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.