# GitHub Actions Permission Auditor (`junipr/github-actions-permission-auditor`) Actor

Audit GitHub Actions workflow YAML files for token permission scope, risky triggers, third-party action pinning, secret usage patterns, OIDC configuration, and workflow-level permission hardening.

- **URL**: https://apify.com/junipr/github-actions-permission-auditor.md
- **Developed by:** [junipr](https://apify.com/junipr) (community)
- **Categories:** Automation
- **Stats:** 2 total users, 1 monthly users, 100.0% runs succeeded, 0 bookmarks
- **User rating**: No ratings yet

## Pricing

from $4.90 / 1,000 page auditeds

This Actor is paid per event. You are not charged for the Apify platform usage, but only a fixed price for specific events.

Learn more: https://docs.apify.com/platform/actors/running/actors-in-store#pay-per-event

## What's an Apify Actor?

Actors are web data automations that power AI and operations. They run on the Apify platform to scrape websites, process data, connect APIs, and automate workflows.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.
Actors are written with capital "A".

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.
The best way to integrate Actors is as follows.

- **AI agents and MCP clients** — the [Apify MCP server](https://docs.apify.com/integrations/mcp.md) at `https://mcp.apify.com` (remote, streamable HTTP, OAuth on first use).
- **Agentic workflows and local Actor development** — [Agent Skills](https://apify.com/.well-known/agent-skills/index.json) with the [Apify CLI](https://docs.apify.com/cli/docs.md): `npm install -g apify-cli`, then `apify login`.
- **JavaScript/TypeScript projects** — the official [JS/TS client](https://docs.apify.com/api/client/js/docs.md): `npm install apify-client`.
- **Python projects** — the official [Python client](https://docs.apify.com/api/client/python/docs.md): `pip install apify-client`.
- **Any other language** — the [REST API](https://docs.apify.com/api/v2.md).

For usage examples, see the [API](#api) section below.

For more details, see Apify documentation as [Markdown index](https://docs.apify.com/llms.txt) and [Markdown full-text](https://docs.apify.com/llms-full.txt).

# README

## GitHub Actions Permission Auditor

### Store Positioning

**Store title:** GitHub Actions Permission Auditor

**Short description:** Audit GitHub Actions workflow YAML files for token permission scope, risky triggers, third-party action pinning, secret usage patterns, OIDC configuration, and workflow-level permission hardening.

**SEO title:** GitHub Actions Permission Auditor — technical SEO, web, and domain audit

**SEO description:** Audit GitHub Actions workflow YAML files for token permission scope, risky triggers, third-party action pinning, secret usage patterns, OIDC configuration, and workflow-level permission hardening. Use it to find crawlability, indexability, security, metadata, and page-quality issues with evidence-backed rows and audit reports.

**Categories:** AUTOMATION

**Keywords:** github, actions, permission, auditor, web/domain audit

### Pay-Per-Event Pricing

This actor uses pay-per-event pricing. Event prices include Apify platform usage; users are not expected to pay a separate platform-usage pass-through charge for the configured pricing model.

- Tier: W1 — Web/domain audit
- Primary event: `page-audited` at $0.00490 base
- Default max charge: $10.00
- Store discounts: FREE/BRONZE base, SILVER discounted, GOLD deepest approved discount

Event set:

- `actor-start`: base $0.00500, GOLD $0.00400. Github Actions Permission Auditor: charged when actor start is completed. The price includes Apify platform usage; no separate usage pass-through is intended.
- `page-audited`: base $0.00490, GOLD $0.00392. Github Actions Permission Auditor: charged when page audited is completed. The price includes Apify platform usage; no separate usage pass-through is intended.
- `record-extracted`: base $0.00372, GOLD $0.00298. Github Actions Permission Auditor: charged when record extracted is completed. The price includes Apify platform usage; no separate usage pass-through is intended.
- `finding-emitted`: base $0.00372, GOLD $0.00298. Github Actions Permission Auditor: charged when finding emitted is completed. The price includes Apify platform usage; no separate usage pass-through is intended.
- `audit-report-generated`: base $0.05000, GOLD $0.04000. Github Actions Permission Auditor: charged when audit report generated is completed. The price includes Apify platform usage; no separate usage pass-through is intended.

The actor accepts `actor-start` before work, accepts the primary event before each dataset row, and accepts the configured report event before writing report files. If `maxChargeUsd` or the live PPE limit blocks a charge, the corresponding row or report is not written.

### Public Task Concepts

- Audit GitHub Actions Permission controls on a capped public sample
- Find high-priority GitHub Actions Permission issues before release
- Validate GitHub Actions Permission evidence from supplied pages
- Prioritize GitHub Actions Permission fixes with severity and proof
- Export GitHub Actions Permission QA rows for client review

Audit GitHub Actions workflow YAML files for token permission scope, risky triggers, third-party action pinning, secret usage patterns, OIDC configuration, and workflow-level permission hardening.

### What it does

- Accept public workflow YAML URLs, raw YAML inputs, or public repository workflow paths.
- Parse workflow and job-level permissions.
- Detect broad token permissions, missing explicit permissions, risky `pull_request_target` usage, unpinned actions, floating action refs, shell injection-prone patterns, secrets exposure patterns, and OIDC permission usage.
- Emit workflow-level and job-level audit rows with severity, evidence, and recommendations.
- Generate action reference inventory and permission matrix.

### What it does not do

- No private repository access unless workflow content is supplied.
- No account modification, exploit generation, secret extraction, CI execution, or official security certification.

### Input fields

Primary inputs from the locked actor spec: `workflowFiles`, `workflowUrls`, `repositoryUrls`, `rawYamlInputs`, `defaultPermissionPolicy`, `allowedActions`, `requireShaPinnedActions`, `includeActionInventory`, `includeTriggerAudit`, `maxWorkflows`, `timeoutMs`. `maxChargeUsd` keeps runs capped during production use.

### Output fields

Dataset rows include: `repositoryUrl`, `workflowPath`, `workflowName`, `jobId`, `triggerName`, `ruleId`, `severity`, `permissionScope`, `permissionValue`, `actionReference`, `pinnedStatus`, `usesSecrets`, `yamlPath`, `evidence`, `recommendation`, `passed`.

### Starter example

Use `examples/input.tiny.json` as a small starter input. Keep the first run capped and review the dataset before increasing limits.

### Public task examples

- Run GitHub Actions Permission Auditor on supplied sample data: Run GitHub Actions Permission Auditor on supplied sample data using a small bounded input.
- Generate a GitHub Actions Permission Auditor QA report: Generate a GitHub Actions Permission Auditor QA report using a small bounded input.
- Find invalid rows with GitHub Actions Permission Auditor: Find invalid rows with GitHub Actions Permission Auditor using a small bounded input.
- Create a capped local endpoint readiness check for GitHub Actions Permission Auditor: Create a capped local endpoint readiness check for GitHub Actions Permission Auditor using a small bounded input.
- Prepare GitHub Actions Permission Auditor output for downstream automation: Prepare GitHub Actions Permission Auditor output for downstream automation using a small bounded input.

### Public source provenance

The starter input audits the public `actions/checkout` test workflow at immutable commit `e8d4307400f9427dba7cb98e488d6ab85f1cec5f`. Public tasks inspect five upstream workflows from that revision for explicit permissions, trigger risks, action references, and secret-context use.

### Reports

- `github-actions-permission-audit.md`
- `workflow-permission-matrix.csv`
- `third-party-action-inventory.json`
- `workflow-trigger-risk-summary.json`
- `unpinned-actions.csv`

### Limitations and safe use

Start with supplied-input runs, then enable live endpoints only with tight caps, domain allowlists, and no secrets in public examples.

# Actor input Schema

## `workflowFiles` (type: `array`):

Workflow Files to inspect during the run.

## `workflowUrls` (type: `array`):

Public workflow URLs to fetch or inspect for GitHub Actions Permission Auditor.

## `repositoryUrls` (type: `array`):

Public repository URLs to fetch or inspect for GitHub Actions Permission Auditor.

## `rawYamlInputs` (type: `array`):

Optional supplied YAML documents to lint or inspect.

## `defaultPermissionPolicy` (type: `string`):

Default Permission Policy that determines how findings are classified.

## `allowedActions` (type: `array`):

Allowed actions for this run. Values outside this list are skipped or flagged.

## `requireShaPinnedActions` (type: `boolean`):

Require SHA pinned actions during validation and flag rows that do not meet the rule.

## `includeActionInventory` (type: `boolean`):

Include action inventory in output rows or reports when available.

## `includeTriggerAudit` (type: `boolean`):

Include trigger audit in output rows or reports when available.

## `maxWorkflows` (type: `number`):

Maximum workflows to process in one run; keep defaults low for safe first runs.

## `timeoutMs` (type: `number`):

Maximum time in milliseconds allowed for the GitHub Actions Permission Auditor operation before it is treated as timed out.

## `maxChargeUsd` (type: `number`):

Maximum estimated PPE charge allowed for the run before the actor stops gracefully.

## Actor input object example

```json
{
  "workflowFiles": [],
  "workflowUrls": [
    "https://raw.githubusercontent.com/actions/checkout/e8d4307400f9427dba7cb98e488d6ab85f1cec5f/.github/workflows/test.yml"
  ],
  "repositoryUrls": [],
  "rawYamlInputs": [],
  "defaultPermissionPolicy": "least-privilege",
  "allowedActions": [],
  "requireShaPinnedActions": true,
  "includeActionInventory": true,
  "includeTriggerAudit": true,
  "maxWorkflows": 1,
  "timeoutMs": 10000,
  "maxChargeUsd": 1
}
```

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {};

// Run the Actor and wait for it to finish
const run = await client.actor("junipr/github-actions-permission-auditor").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = {}

# Run the Actor and wait for it to finish
run = client.actor("junipr/github-actions-permission-auditor").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print(f"💾 Check your data here: https://console.apify.com/storage/datasets/{run.default_dataset_id}")
for item in client.dataset(run.default_dataset_id).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{}' |
apify call junipr/github-actions-permission-auditor --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "type": "http",
            "url": "https://mcp.apify.com/?tools=fetch-actor-details,junipr/github-actions-permission-auditor"
        }
    }
}

```

The hosted server signs you in with OAuth on first connect, so no API token belongs in this config. Clients without OAuth support can send an `Authorization: Bearer <APIFY_API_TOKEN>` header instead, using a token from API & Integrations in Apify Console (https://console.apify.com/settings/integrations).

## OpenAPI specification

Download the OpenAPI definition: https://api.apify.com/v2/actors/HshKvmLUpia7WLwuB/builds/16AhjboYeyCjAt8La/openapi.json
