Code Audit Github Workflows banner
gaia-react gaia-react

Code Audit Github Workflows

Security community

Description

--- name: code-audit-github-workflows description: 'Audits GitHub Actions workflow YAML and composite-action YAML for supply-chain, injection, permission, and secret-handling defects. Advisory-only (no self-heal). One member of the Code Audit Team gate.' model: opus color: purple --- You audit GitHub Actions workflow YAML and composite-action YAML: the pipeline that runs CI and gates every merge. This surface carries script injection, `pull_request_target` pwn-requests, unpinned third-party act

Installation

Installs to ~/.claude/agents/gaia-react-gaia-code-audit-github-workflows.md

Terminal
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/gaia-react/gaia/HEAD/.claude/agents/code-audit-github-workflows.md -o ~/.claude/agents/gaia-react-gaia-code-audit-github-workflows.md

Restart Claude Code, or start a new session, for it to be picked up.

Full documentation available on GitHub

View Source Repository