Back to skill

Security audit

GitHub Actions Generator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward GitHub Actions workflow generator, with some normal workflow-safety caveats but no hidden or malicious behavior found.

Before installing or running this skill, be aware that it writes or overwrites GitHub Actions workflow files in the current repository. Review the generated YAML before committing it, especially action versions, workflow permissions, secrets exposure, and deployment behavior.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
github-actions-generator.sh:18
Finding

Generated GitHub Actions Workflows Use Mutable Action References

Content
View full analysis

Vulnerability Details

File Location: github-actions-generator.sh, lines 18-19 and line 36
Vulnerability Type: Supply-chain risk caused by mutable GitHub Action references
Risk Level: Medium

Vulnerable Code

yaml
# github-actions-generator.sh:18-19
      - uses: actions/checkout@v4
      - uses: actions/setup-node@v4
yaml
# github-actions-generator.sh:36
      - uses: actions/checkout@v4

Technical Analysis

The generator inserts GitHub Actions referenced through major-version tags such as actions/checkout@v4 and actions/setup-node@v4. A major-version tag is a mutable Git reference and can be moved to a different commit after the generated workflow has been reviewed.

Consequently, the code executed by a workflow is not cryptographically bound to the revision originally inspected. If an upstream action repository, maintainer account, release process, or mutable tag is compromised, the generated workflow can execute modified third-party code without any corresponding change in the consuming repository.

This issue applies to both generated workflow types:

  • The CI workflow uses mutable references for actions/checkout and actions/setup-node.
  • The deployment workflow uses a mutable reference for actions/checkout.

Attack Path

  1. A user runs the generator and commits one of the generated workflow files.
  2. The workflow retains an action reference such as actions/checkout@v4.
  3. An attacker compromises the upstream action repository, a maintainer account, or another mechanism capable of changing the referenced tag.
  4. The mutable v4 tag is redirected to an attacker-controlled commit.
  5. A push or pull-request event starts the generated workflow.
  6. GitHub Actions resolves the tag at runtime and executes the attacker-controlled action code.
  7. The malicious action attempts to access repository contents, build artifacts, the workflow token, environment da ...[truncated 981 chars]
Remediation
View remediation

Remediation Suggestions

Pin every third-party GitHub Action to a reviewed full commit SHA rather than a mutable branch, release, or major-version tag. Preserve the human-readable release version in a comment, for example:

yaml
- uses: actions/checkout@FULL_40_CHARACTER_COMMIT_SHA # v4
- uses: actions/setup-node@FULL_40_CHARACTER_COMMIT_SHA # v4

Apply the same remediation to the deployment workflow's actions/checkout reference.

Additional hardening measures should include:

  1. Configure Dependabot or Renovate to propose controlled updates to pinned action SHAs.
  2. Review each proposed SHA update and verify that it belongs to the expected upstream release.
  3. Explicitly define minimal workflow permissions so a compromised action does not receive unnecessary repository write access.
  4. Avoid exposing deployment credentials or other secrets to jobs that do not require them.
  5. Protect workflow-file changes through branch protection and mandatory code review.
  6. Consider organization-level policies that require actions to be pinned to immutable commit SHAs.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The natural-language content in the description and usage sections is presented only in Chinese, which can impose a language requirement on users without opt-in. The policy allows fixed language only when the skill offers a choice or clearly justifies a locale-specific restriction, neither of which appears here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest description is written only in Chinese ("生成 GitHub Actions 工作流"), which indicates a language-specific user experience without any visible opt-in or alternative locale choice. The policy requires avoiding forced language constraints unless the locale limitation is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This shell script creates a directory and writes new GitHub Actions workflow YAML files into the repository, which changes project configuration on disk. Aside from the final success message, there is no user-facing warning, confirmation, or comment/docstring explaining that repository files will be created or overwritten.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.