GitHub Actions Permission Auditor
Pricing
from $4.90 / 1,000 page auditeds
GitHub Actions Permission Auditor
Audit GitHub Actions workflow YAML files for token permission scope, risky triggers, third-party action pinning, secret usage patterns, OIDC configuration, and workflow-level permission hardening.
Pricing
from $4.90 / 1,000 page auditeds
Rating
0.0
(0)
Developer
junipr
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
8 days ago
Last modified
Categories
Share
Store Positioning
Store title: GitHub Actions Permission Auditor
Short description: Audit GitHub Actions workflow YAML files for token permission scope, risky triggers, third-party action pinning, secret usage patterns, OIDC configuration, and workflow-level permission hardening.
SEO title: GitHub Actions Permission Auditor — technical SEO, web, and domain audit
SEO description: Audit GitHub Actions workflow YAML files for token permission scope, risky triggers, third-party action pinning, secret usage patterns, OIDC configuration, and workflow-level permission hardening. Use it to find crawlability, indexability, security, metadata, and page-quality issues with evidence-backed rows and audit reports.
Categories: AUTOMATION
Keywords: github, actions, permission, auditor, web/domain audit
Pay-Per-Event Pricing
This actor uses pay-per-event pricing. Event prices include Apify platform usage; users are not expected to pay a separate platform-usage pass-through charge for the configured pricing model.
- Tier: W1 — Web/domain audit
- Primary event:
page-auditedat $0.00490 base - Default max charge: $10.00
- Store discounts: FREE/BRONZE base, SILVER discounted, GOLD deepest approved discount
Event set:
actor-start: base $0.00500, GOLD $0.00400. Github Actions Permission Auditor: charged when actor start is completed. The price includes Apify platform usage; no separate usage pass-through is intended.page-audited: base $0.00490, GOLD $0.00392. Github Actions Permission Auditor: charged when page audited is completed. The price includes Apify platform usage; no separate usage pass-through is intended.record-extracted: base $0.00372, GOLD $0.00298. Github Actions Permission Auditor: charged when record extracted is completed. The price includes Apify platform usage; no separate usage pass-through is intended.finding-emitted: base $0.00372, GOLD $0.00298. Github Actions Permission Auditor: charged when finding emitted is completed. The price includes Apify platform usage; no separate usage pass-through is intended.audit-report-generated: base $0.05000, GOLD $0.04000. Github Actions Permission Auditor: charged when audit report generated is completed. The price includes Apify platform usage; no separate usage pass-through is intended.
The actor accepts actor-start before work, accepts the primary event before each dataset row, and accepts the configured report event before writing report files. If maxChargeUsd or the live PPE limit blocks a charge, the corresponding row or report is not written.
Public Task Concepts
- Audit GitHub Actions Permission controls on a capped public sample
- Find high-priority GitHub Actions Permission issues before release
- Validate GitHub Actions Permission evidence from supplied pages
- Prioritize GitHub Actions Permission fixes with severity and proof
- Export GitHub Actions Permission QA rows for client review
Audit GitHub Actions workflow YAML files for token permission scope, risky triggers, third-party action pinning, secret usage patterns, OIDC configuration, and workflow-level permission hardening.
What it does
- Accept public workflow YAML URLs, raw YAML inputs, or public repository workflow paths.
- Parse workflow and job-level permissions.
- Detect broad token permissions, missing explicit permissions, risky
pull_request_targetusage, unpinned actions, floating action refs, shell injection-prone patterns, secrets exposure patterns, and OIDC permission usage. - Emit workflow-level and job-level audit rows with severity, evidence, and recommendations.
- Generate action reference inventory and permission matrix.
What it does not do
- No private repository access unless workflow content is supplied.
- No account modification, exploit generation, secret extraction, CI execution, or official security certification.
Input fields
Primary inputs from the locked actor spec: workflowFiles, workflowUrls, repositoryUrls, rawYamlInputs, defaultPermissionPolicy, allowedActions, requireShaPinnedActions, includeActionInventory, includeTriggerAudit, maxWorkflows, timeoutMs. maxChargeUsd keeps runs capped during production use.
Output fields
Dataset rows include: repositoryUrl, workflowPath, workflowName, jobId, triggerName, ruleId, severity, permissionScope, permissionValue, actionReference, pinnedStatus, usesSecrets, yamlPath, evidence, recommendation, passed.
Starter example
Use examples/input.tiny.json as a small starter input. Keep the first run capped and review the dataset before increasing limits.
Public task examples
- Run GitHub Actions Permission Auditor on supplied sample data: Run GitHub Actions Permission Auditor on supplied sample data using a small bounded input.
- Generate a GitHub Actions Permission Auditor QA report: Generate a GitHub Actions Permission Auditor QA report using a small bounded input.
- Find invalid rows with GitHub Actions Permission Auditor: Find invalid rows with GitHub Actions Permission Auditor using a small bounded input.
- Create a capped local endpoint readiness check for GitHub Actions Permission Auditor: Create a capped local endpoint readiness check for GitHub Actions Permission Auditor using a small bounded input.
- Prepare GitHub Actions Permission Auditor output for downstream automation: Prepare GitHub Actions Permission Auditor output for downstream automation using a small bounded input.
Public source provenance
The starter input audits the public actions/checkout test workflow at immutable commit e8d4307400f9427dba7cb98e488d6ab85f1cec5f. Public tasks inspect five upstream workflows from that revision for explicit permissions, trigger risks, action references, and secret-context use.
Reports
github-actions-permission-audit.mdworkflow-permission-matrix.csvthird-party-action-inventory.jsonworkflow-trigger-risk-summary.jsonunpinned-actions.csv
Limitations and safe use
Start with supplied-input runs, then enable live endpoints only with tight caps, domain allowlists, and no secrets in public examples.