CI/CD pipeline security review
SkillSecurityReview CI/CD pipelines for security flaws, poisoned workflows, secret leakage, and injection. Load on GitHub Actions / GitLab CI / Jenkins config, ".github/workflows", pull_request_target, self-hosted runners, or "pipeline security". Signals: workflow YAML, secrets in CI, third-party actions.
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the CI/CD pipeline security review skill
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/code-review/code-review-cicd/SKILL.md and read by ahel’s review.
When it applies
You can read a repo's CI config (GitHub Actions, GitLab CI, Jenkinsfile, CircleCI). Pipelines run with secrets and often on attacker-influenced input (PRs), making them a high-value, under-reviewed target.
Why it works
CI runs code with privileged tokens/secrets. Misconfigurations let a fork PR run in a trusted context, inject commands via untrusted inputs, or exfiltrate secrets — a supply-chain foothold. On public repos this can be exploitable by anyone who opens a PR.
Method
- Dangerous triggers:
pull_request_target/workflow_runthat check out and run PR code with secrets in scope → fork PRs can steal secrets or run arbitrary code (the classic GitHub Actions bug). - Script injection: untrusted data (
github.event.issue.title, PR body, branch name) used directly inrun:shells → command injection. Look for${{ github.event.* }}inrunblocks. - Secret handling: secrets echoed/logged, passed to third-party actions, or available to fork PRs;
overly broad
permissions:(defaultwrite), long-livedGITHUB_TOKEN. - Untrusted dependencies: third-party actions pinned to a mutable tag/branch (not a SHA), curl-pipe-to-shell steps, unpinned package installs → supply-chain.
- Self-hosted runners on public repos: fork PRs executing on your infra → RCE on the runner.
Gotchas
pull_request(safe-ish) vspull_request_target(dangerous) — the trigger name is the crux.- An action pinned to
@v3(tag) can be moved; require a full commit SHA for third-party actions. - Secret leakage often happens via a step passing
${{ secrets.X }}to an untrusted action.
Verify success
A concrete path where an outsider (fork PR / issue) can execute code with pipeline privileges or exfiltrate a secret, or a clear secret-leak/injection in the workflow.
References
GitHub Actions security hardening docs; "GitHub Actions pwn requests" (Nathan Davison); semgrep CI rules.
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
code-review-cicd- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent
Related picks
Skill · tddworks
The pick for GitHub Actionsgithub-actions-docs
Skill · devantler-tech
The pick for GitHub Actionssecrets-exposure-review
Skill · naodeng
The pick for Secretssecrets-with-git-crypt
Skill · derailed-dash
The pick for Secretssupply-chain-risk-auditor
Skill · trailofbits
The pick for Supply Chaincompetition-supply-chain
Skill · alicewe1
The pick for Supply Chain