T08 · Insecure Dependencies
- Location
scripts/adopt.sh:69- Finding
Unreviewed Third-Party GitHub Actions Workflows Are Enabled and Executed
- Content
View full analysis
Vulnerability Details
File Location:
scripts/adopt.sh, lines 69-103
Vulnerability Type: Unsafe third-party workflow dependency and execution
Risk Level: HighComplete Code Snippet
bash # Fork the repo echo "🍴 Forking $SOURCE_REPO..." FORK_RESPONSE=$(curl -s -X POST \ -H "Authorization: token $GITHUB_TOKEN" \ -H "Accept: application/vnd.github.v3+json" \ "https://api.github.com/repos/$SOURCE_REPO/forks" \ -d "{\"name\": \"$REPO_NAME\", \"default_branch_only\": true}") FORK_URL=$(echo "$FORK_RESPONSE" | jq -r '.html_url') if [ "$FORK_URL" == "null" ]; then echo "❌ Failed to fork repo" echo "$FORK_RESPONSE" | jq -r '.message // .errors[0].message // "Unknown error"' exit 1 fi echo "✅ Forked to: $FORK_URL" # Wait for fork to be ready echo "⏳ Waiting for fork to initialize..." sleep 5 # Enable GitHub Actions (they're disabled by default on forks) echo "⚡ Enabling GitHub Actions..." curl -s -X PUT \ -H "Authorization: token $GITHUB_TOKEN" \ -H "Accept: application/vnd.github.v3+json" \ "https://api.github.com/repos/$GITHUB_USER/$REPO_NAME/actions/permissions" \ -d '{"enabled": true, "allowed_actions": "all"}' > /dev/null # Trigger the genesis workflow if it exists echo "🐣 Initializing your pet..." curl -s -X POST \ -H "Authorization: token $GITHUB_TOKEN" \ -H "Accept: application/vnd.github.v3+json" \ "https://api.github.com/repos/$GITHUB_USER/$REPO_NAME/actions/workflows/genesis.yml/dispatches" \ -d '{"ref": "main"}' 2>/dev/null || trueTechnical Analysis
The adoption script forks a mutable repository controlled outside the audited Skill package, enables GitHub Actions with
allowed_actionsset toall, and immediately dispatches the forkedgenesis.ymlworkflow. The source repository is selected from the fixedforkZooorganization, but its content is not pinned to a reviewed commit and no workflow-content verifi ...[truncated 2241 chars]- Remediation
View remediation
Remediation Suggestions
- Pin adoption to a specific reviewed upstream commit or immutable release identifier instead of implicitly trusting the current default branch.
- Retrieve and inspect the workflow files at the pinned revision before enabling GitHub Actions. Verify their contents against a maintained checksum or signature.
- Do not dispatch
genesis.ymlautomatically. Display the workflow source and require explicit user confirmation before enabling or running it. - Replace
"allowed_actions": "all"with a restrictive GitHub Actions policy that permits only GitHub-authored actions and an explicit allowlist of reviewed actions. - Pin every referenced third-party action to a full commit SHA rather than a mutable branch or version tag.
- Configure default workflow permissions as read-only and grant write permissions only to individual jobs that demonstrably require them.
- Avoid exposing repository or organization secrets to the initialization workflow unless essential. Use narrowly scoped, environment-protected secrets where necessary.
- Validate that the forked repository and workflow commit match the expected source and revision before dispatch.
- Surface failures from the permissions and dispatch API calls instead of suppressing errors with redirection and
|| true, so users can verify the resulting security configuration.
