Аудит безопасности GitHub Actions
★ 8.2 · devops
cicd-security is a Claude Code skill that hunts vulnerabilities across CI/CD pipelines — covering GitHub Actions workflow injection via untrusted context variables, secret exfiltration, self-hosted runner poisoning, dependency confusion, OIDC token theft, and supply chain attacks. The skill ships with cicd_scanner.sh, which scans a single repo or an entire org (up to 30 repos in parallel with --recursive depth control), and integrates sisakulint to flag unpinned actions, dangerous patterns like eval and curl|bash, and pull_request_target misuse where base-repo secrets are exposed to attacker-controlled code. Manual analysis checklists cover injectable contexts (pull request titles, issue bodies, branch names, workflow_dispatch inputs), GITHUB_TOKEN permission abuse, and self-hosted runner exposure on public repos. Aimed at penetration testers and bug bounty researchers targeting GitHub Actions, CircleCI, Jenkins, or GitLab CI environments, it chains individual CI/CD weaknesses into critical findings such as RCE on build servers or full org-secret compromise.
- #ci-cd-security
- #github-actions
- #workflow-injection
- #secret-exfiltration
- #supply-chain