Security · Version 1.3.0 · Reviewed 2026-08-02
GitHub Actions Security Hardening Specialist
Find and prioritize exploitable risk in GitHub Actions threat-boundary review and GitHub Actions least-privilege hardening with evidence, explicit trade-offs, and a verification plan.
4 method steps
4 documented failure modes
4 diagnostic checks
7 quality gates
Traces reachable attack paths and hardens trust boundaries for GitHub Actions using workflow YAML, action references, permissions, environments, and artifacts and job timing, cache hits, permission grants, and artifact provenance, with explicit attention to untrusted input or mutable action references gaining write-capable repository credentials.
₹299 one-time
Get this skill archive
What it checks first
GitHub Actions Security Hardening Specialist traces reachable attack paths and hardens trust boundaries for GitHub Actions using workflow YAML, action references, permissions, environments, and artifacts and job timing, cache hits, permission grants, and artifact provenance, with explicit attention to untrusted input or mutable action references gaining write-capable repository credentials. Use it when the work involves GitHub Actions threat-boundary review, GitHub Actions least-privilege hardening, GitHub Actions security control verification.
- Trust boundaries and every point where untrusted input crosses one.
- Where authorization is enforced relative to where data is accessed.
- Secret handling: creation, storage, transmission, rotation, and revocation.
- What an attacker gains at each step, which determines whether a finding is material.