Harden Actions
Description
--- description: Pin GitHub Actions to SHAs, fix permissions, and flag dangerous triggers allowed-tools: Read, Write, Edit, Glob, Grep, Bash(git:*, gh:*, zizmor:*, pip:*, npx:*, curl:*, which:*, brew:*, cargo:*) --- Audit and harden GitHub Actions workflows for supply chain security. **This command takes action by default** - it pins Actions to commit SHAs, sets explicit permissions, and fixes script injection. Changes are explained as they are made. Read `${CLAUDE_PLUGIN_ROOT}/skills/supply-c
Installation
Installs to ~/.claude/skills/latiotech-secure-supply-chain-skills-harden-actions/SKILL.md
mkdir -p ~/.claude/skills/latiotech-secure-supply-chain-skills-harden-actions && curl -fsSL https://raw.githubusercontent.com/latiotech/secure-supply-chain-skills/HEAD/commands/harden-actions.md -o ~/.claude/skills/latiotech-secure-supply-chain-skills-harden-actions/SKILL.md Restart Claude Code, or start a new session, for it to be picked up.
Full documentation available on GitHub
View Source RepositoryRelated Skills
Epic Sync
Sync epic issue bodies, labels, and local coordination snapshots from GitHub.
Git 使用 Git Worktrees
创建孤立的 Git worktrees,带有智能目录选择与安全验证。
Git Claude skills github
[Building agent skills blog](https://www.anthropic.com/engineering/equipping-agents-for-the-real-world-with-ag
Git #148
, [#161](https://github.com/affaan-m/everything-claude-code/pull/161))
Git GitHub MCP
| Token | Repos, issues, PRs, workflows |
Git GitHub MCP Server
Official first-party server to read repos, manage issues/PRs, and automate workflows.
Git