agentic-actions-auditor

SkillSecurity

Lets your agent scan GitHub Actions workflows for security holes where attackers can hijack AI tools running in them.

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the agentic-actions-auditor skill

About this capability

Audits GitHub Actions workflows for security vulnerabilities in AI agent integrations including Claude Code Action, Gemini CLI, OpenAI Codex, and GitHub AI Inference. Detects attack vectors where attacker-controlled input reaches AI agents running in CI/CD pipelines, including env var intermediary p

Signals

GitHub stars
7k
Forks
604
Last commit
Sep 2026
Advanced
Catalog kind
skill
Gateway key
agentic-actions-auditor-trailofbits
Source
github.com/trailofbits/skills