offensive-cicd-pipeline

SkillAI & models

Teaches your agent how CI/CD systems like GitHub Actions and Jenkins can be attacked, for security testing.

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the offensive-cicd-pipeline skill

About this capability

Comprehensive CI/CD pipeline exploitation methodology covering GitHub Actions injection vectors (expression injection via PR titles and issue bodies, workflow_run event abuse, GITHUB_TOKEN over-scoping, composite action supply chain compromise), Jenkins attack paths (Groovy sandbox escapes, script c

Signals

GitHub stars
4k
Forks
597
Last commit
Aug 2026
Advanced
Catalog kind
skill
Gateway key
offensive-cicd-pipeline
Source
github.com/snailsploit/claude-red