github-actions-hardening
github/awesome-copilotSecurity hardening reviewer for GitHub Actions workflow files (.github/workflows/*.yml). Reasons about the Actions threat model that pattern matchers and…
Scores out of 100 · grade A+
2026-08-22Works
40% of the score100/100
- Loads cleanly: valid frontmatter, required fields present, no dangling references.
Maintained
25% of the score100/100
- no commits in the last 12 weeks
Adopted
20% of the score63/100
- 38,112 stars on the source repo.
Documented
15% of the score82/100
- 1,250 words with worked examples.
- Ships 5 bundled files.
Install
npx skills add github/awesome-copilot/github-actions-hardeningWhat it says it does
Security hardening reviewer for GitHub Actions workflow files (.github/workflows/*.yml). Reasons about the Actions threat model that pattern matchers and general code linters miss — untrusted-input script injection, privileged triggers running fork code, mutable action references, and over-scoped tokens. Use this skill when asked to review, audit, harden, or secure a GitHub Actions workflow, when writing a new workflow, or for any request like "is this workflow safe?", "review my CI for security issues", "why is pull_request_target dangerous here?", "pin my actions", or "lock down GITHUB_TOKEN permissions". Covers script injection via ${{ }} interpolation, pull_request_target / workflow_run privilege escalation, SHA-pinning of third-party actions, least-privilege permissions, GITHUB_ENV/GITHUB_OUTPUT injection, secret exposure, OIDC over long-lived credentials, and self-hosted runner exposure on public repositories.
Also in github/awesome-copilot
| Artifact | Score | What the check found | Type | Reach | Last commit |
|---|---|---|---|---|---|
| code-tourgithub/awesome-copilot | clean | Skill | 38k stars | today | |
| convert-excel-to-mdgithub/awesome-copilot | clean | Skill | 38k stars | today | |
| convert-pdf-to-mdgithub/awesome-copilot | clean | Skill | 38k stars | today | |
| convert-word-to-mdgithub/awesome-copilot | clean | Skill | 38k stars | today | |
| github-issuesgithub/awesome-copilot | clean | Skill | 14,854 installs | today | |
| namecheapgithub/awesome-copilot | clean | Skill | 38k stars | today |
Other security skills
Browse all| Artifact | Score | What the check found | Category | Reach | Last commit |
|---|---|---|---|---|---|
| release-openclaw-ciopenclaw/openclaw | No license | Security | 387k stars | today | |
| site-architecturecoreyhaines31/marketingskills | clean | Security | 94,902 installs | today | |
| cookbook-auditanthropics/claude-cookbooks | clean | Security | 52k stars | 2 days ago | |
| asocoreyhaines31/marketingskills | clean | Security | 46,665 installs | today | |
| openclaw-secret-scanning-maintaineropenclaw/openclaw | No license | Security | 387k stars | today | |
| graph-evolutiontrailofbits/skills | clean | Security | 2,860 installs | today |
Put this measurement in your README
A badge carrying how many listings this index holds from the repository and how many pass every static structural check. It reads from this index every time somebody loads your page, so it changes when the measurement changes and there is nothing to keep up to date. Free, no account, and the value is not something you or we can set by hand.
[](https://skillworks.kynth.studio/?q=github%2Fawesome-copilot)Would rather not hotlink us? Every badge is also served in shields.io’s endpoint schema, so shields renders the image and your readers never talk to our domain:
Published by Toolproof, the masthead over this index and eight others. The method behind the number is at toolproof.kynth.studio/methodology, and the whole thing is readable as JSON with no key at /api.
