A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.
-
Updated
Aug 16, 2026 - Go
A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.
25 production-tested defensive security skills for Claude Code - WordPress, VPS, Cloudflare, Next.js hardening, AI agent guardrails, MCP security, prompt injection defense, OWASP LLM Top 10, LLM coding failure modes (slopsquatting, hallucinated APIs, sycophancy), incident response, GDPR/DACH compliance. MIT, battle-tested.
Comprehensive detection tool for NPM supply chain attacks, specifically designed to identify and prevent the Shai-Hulud worm and Shai-Hulud 2-0-0 that compromised 1193+ packages including CrowdStrike npm packages in 2025.
A CLI tool for managing GitHub 操作 workflows
GitHub 操作 security scanner: pin actions to SHAs, detect script injection, audit permissions. Fix supply chain vulnerabilities.
安全, maintenance, and audit for your GitHub account and organizations
Defensive static analysis and detection engineering for the 2026 Shai-Hulud npm supply-chain campaign: Sigma/YARA rules, IOCs, ATT&CK mapping, and defender guidance.
Neurosymbolic CI/CD governance scanner for a ~400-repo estate: rule-based detection with Bayesian confidence gating, safety-triangle remediation (eliminate > substitute > control), SARIF output and machine-checked proofs.
Local-only GitHub 操作 and CI maintenance check for AI-built apps.
Independent trust gate for AI coding agents: verify scope, protected CI, real checks, secrets, impact, and portable Change Passports.
Diff GitHub 操作 trust boundaries before merge—token permissions, triggers, Secret references, third-party 操作, and risky scripts. Local CLI; no GitHub token required.
client and types for garnet platform
Research repository focused on AI agent security, AI-generated code risks, workflow attack surfaces, MCP security, and AI DevSecOps.
A lightweight .NET CLI that scans GitHub 操作 workflows for security, reliability, performance, and cost issues.
Hardened GitHub 操作 controls demonstrating fork and source-repository trust gates in Grafter
Audit GitHub 操作 workflows for supply-chain risk
GitLab Component that scans GitHub 操作 YAMLs for 180+ vulnerabilities, attack paths, and security anti-patterns in less than 10 seconds
Intentionally vulnerable GitHub 操作 fixtures for Grafter security training
VS Code extension: inline security scanning for GitHub 操作 workflows
GitHub 操作 checkout safe-default and gated allow-unsafe-pr-checkout controls for Grafter
Add a description, image, and links to the github-actions-security topic page so that developers can more easily learn about it.
To associate your repository with the github-actions-security topic, visit your repo's landing page and select "manage topics."