| name | agentic-actions-auditor |
| description | Audits GitHub Actions workflows for security vulnerabilities in AI agent integrations including Claude Code Action, Gemini CLI, OpenAI Codex, and GitHub AI Inference. Detects attack vectors where attacker-controlled input reaches AI agents running in CI/CD pipelines, including env var intermediary patterns, direct expression injection, dangerous sandbox configurations, and wildcard user allowlists. Use when. |
| source_skill_id | trailofbits-skills-plugins-agentic-actions-auditor-skills-agentic-actions-auditor-skill-md |
| category | Security, compliance & risk |
| source_mirror | ../../../../../skills/by-category/security-compliance-risk/security-reference/agentic-actions-auditor/SKILL.md |
| benchmark_status | artifact_gated |
agentic-actions-auditor
Use this skill when the task matches the description above or the source path clearly applies. Start with this concise entrypoint; open ../../../../../skills/by-category/security-compliance-risk/security-reference/agentic-actions-auditor/SKILL.md only when implementation details, commands, assets, or references are needed.
Workflow
- Confirm the task matches this skill's scope.
- Read the local source mirror if more detail is required.
- Follow repository-level
AGENTS.md; use one AI session only.
- Keep claims tied to files, commands, citations, or benchmark artifacts.
Verification
- Source mirror:
../../../../../skills/by-category/security-compliance-risk/security-reference/agentic-actions-auditor/SKILL.md
- Source commit:
e8cc5baf9329ccb491bfa200e82eacbac83b1ead
- Static benchmark results: see
docs/benchmark-results.md
- Runtime artifacts recorded by this entrypoint:
0
- Assigned scenarios:
skill-proof-trailofbits-skills-plugins-agentic-actions-auditor-skills-agentic-actions-auditor-skill-md, security-compliance-and-risk-owasp-benchmark, security-compliance-and-risk-owasp-juice-shop, security-compliance-and-risk-kubernetes-examples
Do not claim this skill passed a runtime benchmark until a validated artifact exists.