BigHugger
sk Skill · elementalsouls

hunt-cicd

Hunt CI/CD pipeline vulnerabilities — GitHub Actions workflow injection (pull_request_target Pwnrequest + ${{ }}-into-shell), self-hosted runner poisoning, OIDC trust-policy abuse, Jenkins script-console RCE and CVE-2024-23897 file read, GitLab CI runner-token registration, Terraform state file leakage, artifact/log secret leakage, pipeline env-var disclosure. Use when target has a public GitHub/GitLab org, exposed…

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
yamlgroovybashPython
Host repository
elementalsouls/Claude-BugHunter
Host stars
4,524
Host language
Python