Harden Actions — Git skill for Claude Code
Pin GitHub Actions to SHAs, fix permissions, and flag dangerous triggers.
How to install Harden Actions
Installs to ~/.claude/skills/latiotech-secure-supply-chain-skills-harden-actions/SKILL.md
mkdir -p ~/.claude/skills/latiotech-secure-supply-chain-skills-harden-actions && curl -fsSL https://raw.githubusercontent.com/latiotech/secure-supply-chain-skills/HEAD/commands/harden-actions.md -o ~/.claude/skills/latiotech-secure-supply-chain-skills-harden-actions/SKILL.md Restart Claude Code, or start a new session, for it to be picked up.
What Harden Actions does
description: Pin GitHub Actions to SHAs, fix permissions, and flag dangerous triggers allowed-tools: Read, Write, Edit, Glob, Grep, Bash(git:*, gh:*, zizmor:*, pip:*, npx:*, curl:*, which:*, brew:*, cargo:*)
Audit and harden GitHub Actions workflows for supply chain security. **This command takes action by default** - it pins Actions to commit SHAs, sets explicit permissions, and fixes script injection. Changes are explained as they are made.
Read `${CLAUDE_PLUGIN_ROOT}/skills/supply-c
Alternatives in Git
- Fix PR — by metabase - Fetches and fixes unresolved PR comments by automatically retrieving feedback, addressing review 46.5k ★
- Gh Fix CI — Debug and fix failing GitHub Actions PR checks using log inspection 14.6k ★
- Triage Issues — Triage open GitHub issues — split into bugs vs features, rank by severity/opportunity, and flag under-specifie 12.6k ★
Full documentation available on GitHub
View Source RepositoryRelated Skills
Publish MCP Server
Publishes one of the bundled MCP servers to npm. Tag push triggers GitHub Actions → npm publish --provenance.
Drift Fix
Resolve upstream fork-drift end-to-end — run the drift guard, mechanically bump every auto-bumpable pin, land
Fix CI
Analyze Github Actions logs and fix issues
Destructive Command Guard
The Destructive Command Guard (dcg) is for blocking dangerous git and shell commands from being executed by ag
Harden Credentials
Scan for leaked secrets, set up pre-commit hooks, and harden credential hygiene
Se Irr
Assumption Review — detect unproven assumptions, pin them in a commit-stamped record, promote the load-bearing
Related Agents
Prerelease
Use this agent to create a prerelease PR that triggers the automated GitHub Actions release workflow with the
PR Security Review
Use this agent to perform a security analysis of a pull request BEFORE checking out or running any code locall
Block Docs Writer
Use this agent when one named documentation block must be written or refreshed from code or a spec, with its o