Agentic GitHub Actions Auditor
trailofbits/skills
Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.
Deep audit before GitHub push: removes junk files, dead code, security holes, and optimization issues.
$ npx skills add sickn33/agentic-awesome-skills --skill codebase-audit-pre-push -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install sickn33/agentic-awesome-skills codebase-audit-pre-push --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/codebase-audit-pre-push .claude/skills/codebase-audit-pre-push && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "codebase-audit-pre-push" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/codebase-audit-pre-push into .claude/skills/codebase-audit-pre-push/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codebase-audit-pre-push", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/codebase-audit-pre-pushType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add sickn33/agentic-awesome-skills --skill codebase-audit-pre-push -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install sickn33/agentic-awesome-skills codebase-audit-pre-push --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/codebase-audit-pre-push .agents/skills/codebase-audit-pre-push && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "codebase-audit-pre-push" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/codebase-audit-pre-push into .agents/skills/codebase-audit-pre-push/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codebase-audit-pre-push", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add sickn33/agentic-awesome-skills --skill codebase-audit-pre-push -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install sickn33/agentic-awesome-skills codebase-audit-pre-push --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/codebase-audit-pre-push .cursor/skills/codebase-audit-pre-push && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "codebase-audit-pre-push" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/codebase-audit-pre-push into .cursor/skills/codebase-audit-pre-push/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codebase-audit-pre-push", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/sickn33/agentic-awesome-skills.git --path skills/codebase-audit-pre-push--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add sickn33/agentic-awesome-skills --skill codebase-audit-pre-push -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install sickn33/agentic-awesome-skills codebase-audit-pre-push --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/codebase-audit-pre-push .gemini/skills/codebase-audit-pre-push && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "codebase-audit-pre-push" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/codebase-audit-pre-push into .gemini/skills/codebase-audit-pre-push/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codebase-audit-pre-push", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install sickn33/agentic-awesome-skills codebase-audit-pre-pushInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add sickn33/agentic-awesome-skills --skill codebase-audit-pre-push -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/codebase-audit-pre-push .github/skills/codebase-audit-pre-push && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "codebase-audit-pre-push" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/codebase-audit-pre-push into .github/skills/codebase-audit-pre-push/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codebase-audit-pre-push", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add sickn33/agentic-awesome-skills --skill codebase-audit-pre-push -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install sickn33/agentic-awesome-skills codebase-audit-pre-push --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/codebase-audit-pre-push .opencode/skills/codebase-audit-pre-push && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "codebase-audit-pre-push" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/codebase-audit-pre-push into .opencode/skills/codebase-audit-pre-push/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codebase-audit-pre-push", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
codebase-audit-pre-pushDeep audit before GitHub push: removes junk files, dead code, security holes, and optimization issues.
Codebase Audit Pre Push is an agent skill from sickn33/agentic-awesome-skills. Deep audit before GitHub push: removes junk files, dead code, security holes, and optimization issues. Checks every file line-by-line for production readiness.
Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Security review. It works with GitHub. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.
10 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 1e53ce2. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Codebase Audit Pre Push loads about 2.1k tokens when it runs. Until then it costs about 46 tokens; SKILL.md has 913 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
- `.env` files (should never be committed)- .env (contained secrets)PI key in config.js (line 12) → moved to .envAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from sickn33/agentic-awesome-skills at commit 1e53ce2, republished under its MIT licence (© sickn33). 913 words, ~2,108 tokens.
.claude/skills/codebase-audit-pre-push/SKILL.md (or your agent's skills folder).As a senior engineer, you're doing the final review before pushing this code to GitHub. Check everything carefully and fix problems as you find them.
Review the entire codebase file by file. Read the code carefully. Fix issues right away. Don't just note problems—make the necessary changes.
Start by looking for files that shouldn't be on GitHub:
Delete these immediately:
.DS_Store, Thumbs.db, desktop.ini *.log, npm-debug.log*, yarn-error.log* *.tmp, *.temp, *.cache, *.swp dist/, build/, .next/, out/, .cache/ node_modules/, vendor/, __pycache__/, *.pyc .idea/, .vscode/ (ask user first), *.iml, .project *.bak, *_old.*, *_backup.*, *_copy.* coverage/, .nyc_output/, test-results/ TODO.txt, NOTES.txt, scratch.*, test123.*Critical - Check for secrets:
.env files (should never be committed) password, api_key, token, secret, private_key *.pem, *.key, *.cert, credentials.json, serviceAccountKey.jsonIf you find secrets in the code, mark it as a CRITICAL BLOCKER.
Check if the .gitignore file exists and is thorough. If it’s missing or not complete, update it to include all junk file patterns above. Ensure that .env.example exists with keys but no values.
Look through each code file and check:
Dead Code (remove immediately):
return, inside if (false)) Code Quality (fix issues as you go):
data, info, temp, thing → rename to be descriptive if (status === 3) → extract to named constant console.log, print(), debugger any: add proper types or explain why any is used === instead of == in JavaScript Logic Issues (critical):
.catch() or try/catch default in switch statementsSecrets: Search for hardcoded passwords, API keys, and tokens. They must be in environment variables.
Injection vulnerabilities:
exec() with user-provided input innerHTML or dangerouslySetInnerHTML with user dataAuth/Authorization:
Data exposure:
Dependencies:
npm audit or an equivalent tool Database:
SELECT *: specify columnsAPI Design:
Code:
Organization:
Separation of concerns:
Reusability:
Backend:
Frontend (if applicable):
README.md must include:
Code comments:
test.only or fdescribe should remain in the code test.skip without an explanation After making all changes, run the app. Ensure nothing is broken. Check that:
After auditing, provide a report:
CODEBASE AUDIT COMPLETE
FILES REMOVED:
- node_modules/ (build artifact)
- .env (contained secrets)
- old_backup.js (unused duplicate)
CODE CHANGES:
[src/api/users.js]
✂ Removed unused import: lodash
✂ Removed dead function: formatOldWay()
🔧 Renamed 'data' → 'userData' for clarity
🛡 Added try/catch around API call (line 47)
[src/db/queries.js]
⚡ Fixed N+1 query: now uses JOIN instead of loop
SECURITY ISSUES:
🚨 CRITICAL: Hardcoded API key in config.js (line 12) → moved to .env
⚠️ HIGH: SQL injection risk in search.js (line 34) → fixed with parameterized query
SCALABILITY:
⚡ Added pagination to /api/users endpoint
⚡ Added index on users.email column
FINAL STATUS:
✅ CLEAN - Ready to push to GitHub
Scores:
Security: 9/10 (one minor header missing)
Code Quality: 10/10
Scalability: 9/10
Overall: 9/10 @security-auditor - Deeper security review @systematic-debugging - Investigate specific issues @git-pushing - Push code after audit© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/codebase-audit-pre-push of sickn33/agentic-awesome-skills.
Open the folder on GitHubat commit 1e53ce2
We found 11 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.
Codebase Audit Pre Push next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Codebase Audit Pre Push this skillsickn33/agentic-awesome-skills | 47k | 2 repos | ~2.1k | Automated safety check: Notes | MIT | |
| Agentic GitHub Actions Auditortrailofbits/skills | 7.4k | 6 repos | ~5.4k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Audit Scopeforefy/.context | 152 | — | ~2.3k | Automated safety check: Pass | MIT | |
| Security SecretsIgorWarzocha/Opencode-Workflows | 122 | — | ~1.2k | Automated safety check: Notes | None | |
| Hunter 22aeonfun/aeon | 767 | — | ~1.7k | Automated safety check: Pass | MIT | |
| Repo SentinelMathews-Tom/armory | 327 | — | ~2.2k | Automated safety check: Pass | MIT |
trailofbits/skills
Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.
forefy/.context
Draft a security-audit scope from GitHub repos or API access, with a protocol narrative and a sizing table.
IgorWarzocha/Opencode-Workflows
Review secret detection patterns and scanning workflows. An agent skill from IgorWarzocha/Opencode-Workflows.
aeonfun/aeon
Scan the ClawHunter agent bounty marketplace for opportunities that genuinely match this agent's real capabilities (code, security research, writing) and surface only real matches — never a raw…
Mathews-Tom/armory
Full security audit for public repositories across 12 attack surfaces: git history, secrets, CI/CD, containers, dependencies, licenses.
kedro-org/kedro
Run a Kedro security scan on the full codebase or just a pull request.
sickn33/agentic-awesome-skills
Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.
sickn33/agentic-awesome-skills
Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.
sickn33/agentic-awesome-skills
Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.
sickn33/agentic-awesome-skills
Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.
sickn33/agentic-awesome-skills
Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.
sickn33/agentic-awesome-skills
Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.
Works with
Categories
Deep audit before GitHub push: removes junk files, dead code, security holes, and optimization issues. Codebase Audit Pre Push is an agent skill from sickn33/agentic-awesome-skills. Deep audit before GitHub push: removes junk files, dead code, security holes, and optimization issues.
Codebase Audit Pre Push fits situations like: tasks that involve Security review.
Run `npx skills add sickn33/agentic-awesome-skills --skill codebase-audit-pre-push -a claude-code`. Or copy the skill folder (skills/codebase-audit-pre-push in sickn33/agentic-awesome-skills) into .claude/skills/codebase-audit-pre-push in your project. Claude Code loads it when a task matches its description.
Run `npx skills add sickn33/agentic-awesome-skills --skill codebase-audit-pre-push -a codex`. Or copy the skill folder (skills/codebase-audit-pre-push in sickn33/agentic-awesome-skills) into .agents/skills/codebase-audit-pre-push in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill codebase-audit-pre-push -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/codebase-audit-pre-push, .gemini/skills/codebase-audit-pre-push, .github/skills/codebase-audit-pre-push and .opencode/skills/codebase-audit-pre-push in your project.
Going by SKILL.md and its folder, Codebase Audit Pre Push needs the command-line tools its instructions call (npm).
SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Codebase Audit Pre Push is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.1k tokens (SKILL.md is roughly 8.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Codebase Audit Pre Push: Agentic GitHub Actions Auditor (trailofbits/skills, 7.4k stars), Audit Scope (forefy/.context, 152 stars), Security Secrets (IgorWarzocha/Opencode-Workflows, 122 stars) and Hunter 22 (aeonfun/aeon, 767 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,304 GitHub stars. The repository holds 1,394 skills in this directory. The repository was last updated on October 6, 2026.
Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.