Agentic Actions Auditor
插件 活跃Audits GitHub Actions workflows for security vulnerabilities in AI agent integrations (Claude Code Action, Gemini CLI, OpenAI Codex, GitHub AI Inference)
To help security auditors and developers identify and remediate security risks in GitHub Actions workflows that integrate AI agents, ensuring secure CI/CD pipelines.
功能
- Audits GitHub Actions workflows for AI agent security vulnerabilities
- Detects specific attack vectors like env var intermediary, direct expression injection, and wildcard allowlists
- Supports multiple AI agent integrations (Claude Code, Gemini CLI, OpenAI Codex, GitHub AI Inference)
- Provides detailed findings with impact, evidence, data flow, and remediation guidance
使用场景
- Auditing CI/CD pipelines that use AI agents for security risks
- Reviewing GitHub Actions workflow configurations for prompt injection vulnerabilities
- Ensuring secure defaults for AI-assisted code review and agentic actions
- Assessing the security impact of attacker-controlled input on AI agents running in CI
非目标
- Performing runtime prompt injection testing or exploitation
- Auto-fixing or modifying workflow files
- Auditing non-GitHub CI/CD systems
- Analyzing workflows that do not use AI agent actions
Trust
- warning:Issues AttentionThere are 13 open issues and 4 closed issues in the last 90 days, indicating slow issue closure and potential maintainer bottleneck.
安装
请先添加 Marketplace
/plugin marketplace add trailofbits/skills/plugin install agentic-actions-auditor@trailofbits质量评分
类似扩展
Agent Almanac
99350 agentic skills across 64 domains, 72 agent personas, and 16 team compositions following the agentskills.io open standard
Ruflo Security Audit
99Security review, dependency scanning, policy gates, and CVE monitoring
Shell Scripting Plugins
99Production-grade Bash scripting with defensive programming, POSIX compliance, and comprehensive testing
Review Agent Governance
99Require a human approval signal before an AI agent can post PR reviews, comments, merges, or writes to CI config. Cedar-gated, receipt-signed, designed for the Hermes-style failure mode where a review bot posts without oversight.
Performance Testing Review
99Performance analysis, test coverage review, and AI-powered code quality assessment
Comprehensive Review
99Multi-perspective code analysis covering architecture, security, and best practices