本文へ移動
cccskills
無料GitHub で公開

GitHub Actions Workflow Security Review

Reviews GitHub Actions workflow diffs for script injection of untrusted input, pull_request_target with untrusted checkout, over-broad GITHUB_TOKEN permissions, and unpinned third-party actions.

インストール方法を見る

含まれるファイル(4)

  • SKILL.md4.2 KB
  • fixtures/01-script-injection-happy.md969 B
  • fixtures/02-safe-fields-guard.md915 B
  • golden/01-script-injection-happy.md800 B

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Pattern declaration

Primary pattern: Reviewer Secondary patterns: Inversion Why: workflow の意味的なセキュリティ判断(権限の必要性・トリガーの用途)に集中し、決定論ツールが見ない文脈を検査する

Goal / 目的

  • untrusted input の式展開によるスクリプトインジェクションと、特権トリガー + untrusted checkout(pwn request)を検出する。
  • GITHUB_TOKEN の過剰権限と third-party action の未ピン留めを検出する。

Non-goals / 扱わないこと

  • 構文的に決定論で判定できる領域(pinned-dependencies / token-permissions の機械検出)は OpenSSF Scorecard / zizmor / CodeQL に委ねる(重複指摘しない)。
  • workflow のロジック・効率(セキュリティ以外)。

Pre-execution Gate / 実行前ゲート

このスキルは以下の条件がすべて満たされない限りNO_REVIEWを返す。

  • 差分に .github/workflows/ 配下の追加変更が含まれている
  • diff コンテキストが利用可能である

ゲート不成立時の出力: NO_REVIEW: gha-workflow-security — workflow の変更なし

False-positive guards / 抑制条件

  • 同一 repo / 自 org 内 action(./.github/actions/...、自 org reusable workflow)はピン留め不要とする運用が一般的。minor 以下に留める。
  • actions/* 公式 action の tag 運用は third-party より低リスク。minor 扱い。
  • if: 条件式内の式展開、github.event.*.number / github.sha / github.actor 等の数値・制約付きフィールドは原則安全。
  • checkout なし、または base ref checkout のみの pull_request_target は安全パターン。
  • repo 可視性が不明な self-hosted runner は major でなく warning + 確認依頼にする。

Rule / ルール

  • 攻撃者制御フィールド(github.event.issue.title/.body、pull_request.title/.body/.head.ref、comment.body、commits.*.message、github.head_ref 等)を run: に直接式展開しない。env: 経由で変数化する。
  • pull_request_target / issue_comment / workflow_run で head.sha / head.ref を checkout して PR 由来コードを実行しない(secrets + write 権限の文脈での RCE)。
  • permissions は top-level を contents: read にし、write は必要な job 単位で昇格する(write-all を避ける)。
  • third-party action は full-length commit SHA でピン留めする(バージョンコメント併記を推奨)。

Evidence / 根拠の取り方

  • 指摘は <file>:<line> で差分に紐づけ、出典(securitylab.github.com / docs.github.com の secure-use)を 1 行で添える。
  • 重要度: untrusted input の run: 直挿し / pull_request_target + head checkout = critical、permissions 過剰 / public self-hosted = major、tag ピン / persist-credentials = minor。

Output / 出力(短文版の推奨)

コメントは日本語で返す。

  • Finding: インジェクション / pwn request / 過剰権限 / 未ピンのどれか(1文)
  • Impact: RCE / secrets 漏えい / 権限昇格
  • Fix: env 経由 / トリガー分離 / job 単位 permissions / SHA ピンの最小案

Sources / 出典

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

<What this skill does>

日本語の概要は準備中です。原文の説明を表示しています。

s977043/river-review42026年10月11日 更新

a11y Accessible Name Basics

無料日本語概要

画像・ボタン・フォーム要素に適切なアクセシブルネームがあるか確認する。

s977043/river-review42026年10月11日 更新

Ensure ADRs capture context, decision, alternatives, tradeoffs, and follow-ups in a way that prevents future drift.

日本語の概要は準備中です。原文の説明を表示しています。

s977043/river-review42026年10月11日 更新

adversarial-review

無料日本語概要

敵対的分析手法を統合したレビューの entry skill。認知バイアス対策の3手法 (Pre-mortem / War Game / Logic Torturing)と、宣言・主張と実態の乖離を突く claim-vs-actual 検出3パターン(Self-Contradiction / Refactor-Claim Audit / Cross-File Leakage)へルーティングし、通常のレビューでは見えない設計の盲点・ 防御の穴・論理の弱点・宣言と実装のズレを可視化する。

s977043/river-review42026年10月11日 更新

Review changes to the Agent Skills import/export bridge for path safety, round-trip fidelity, and validation correctness.

日本語の概要は準備中です。原文の説明を表示しています。

s977043/river-review42026年10月11日 更新

Checks whether AI-assisted work defines review criteria, accessible context, explicit review loop, human judgment boundary, and feedback capture before delegating to an agent.

日本語の概要は準備中です。原文の説明を表示しています。

s977043/river-review42026年10月11日 更新

s977043 のスキルをすべて見る

このスキルの問題を報告する