GitHub Actions Workflow Security Auditor
Pricing
from $6.00 / 1,000 workflow security audits
GitHub Actions Workflow Security Auditor
Audit workflow YAML for unpinned actions, excessive permissions, untrusted interpolation, risky pull_request_target use and self-hosted runners.
Pricing
from $6.00 / 1,000 workflow security audits
Rating
0.0
(0)
Developer
Q Services
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
6 days ago
Last modified
Categories
Share
Audit GitHub Actions YAML before merge or on a schedule. The Actor returns one dataset item per workflow with a score and deterministic findings.
Checks include immutable action pins, least-privilege permissions,
pull_request_target, untrusted event interpolation in shell commands,
self-hosted runners, checkout credential persistence and download-to-shell
patterns.
No repository token, checkout or external service is required. Workflow contents are parsed locally and are not returned in the dataset.
Pricing is pay per event: one Actor-start event and one event per workflow.