BigHugger
sk Skill · apache

magpie-workflow-security-audit

Read-only GitHub Actions workflow security audit for one repository, an explicit repository set, or a whole GitHub org. Runs zizmor to surface injection vulnerabilities, excessive permissions, unpinned external actions, and self-hosted-runner fork-secret leaks. Produces a grouped, prioritised finding report; never edits workflow files, opens PRs, or posts comments.

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
yamlbashPython
Host repository
apache/magpie
Licence
Apache-2.0
Host stars
96
Host language
Python