Skip to content
Back to skills

Github Actions

ASecurity

Use when editing repository GitHub Actions workflows or generated Golden Path workflows.

  • 2 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 4, 2026
ai-agentsrustgoshellazuregit

Security analysis

A100/100

Scanned September 4, 2026

npx -y skills add paulasilvatech/awesome-harness-primitives --skill github-actions --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Github Actions?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Github Actions
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/paulasilvatech-github-actions/badge)](https://www.skillsdirectory.com/skills/paulasilvatech-github-actions)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: github-actions
description: Use when editing repository GitHub Actions workflows or generated Golden Path workflows.
paths:
  - ".github/workflows/*.yml"
  - scripts/golden-paths/**/.github/workflows/*.yaml
user-invocable: false
---

<!-- Generated from harness/github-copilot/plugins/open-horizons-platform/instructions/github-actions.instructions.md by harness/claude-code/scripts/convert_from_copilot.py. Edit the source, not this file. -->

# GitHub Actions

## Conventions

- Set least-privilege `permissions` at workflow or job scope and grant write permissions only to the job that needs them.
- Pin third-party actions to immutable commit SHAs; retain a version comment for maintainability.
- Use GitHub OIDC for Azure and cloud access, not stored service-principal secrets.
- Treat pull-request content, issue fields, branch names, matrix values, and action outputs as untrusted; pass them through environment variables rather than shell interpolation.
- Keep deployment environments protected and bind approvals to immutable artifacts or plans.
- Bound triggers and path filters so generated or unrelated changes do not gain deployment authority.
- Give jobs timeouts, explicit shells, deterministic dependency restoration, and useful failure summaries.
- Keep generated workflows under `scripts/golden-paths/` portable and free of repository-specific secrets.

## Verification

- Workflow syntax and repository policy checks pass.
- Actions are immutable-pinned and permissions match job behavior.
- Fork and untrusted-input paths cannot reach secrets, OIDC tokens, or protected environments.

## Do / Do Not

| Do | Do not |
| --- | --- |
| Pin actions, minimize permissions, and treat external inputs as untrusted. | Interpolate untrusted values into shell code or grant broad write access. |
| Bind protected operations to immutable artifacts and environments. | Let fork or issue input reach secrets, OIDC, or deployment authority. |

## Checklist Before Opening a PR

- [ ] The change matches this instruction's `applyTo` scope.
- [ ] Syntax, action pins, permissions, and timeouts validate.
- [ ] Untrusted-input paths cannot reach secrets or protected environments.
- [ ] Deployment jobs consume immutable reviewed artifacts.
- [ ] No unrelated edits or unresolved placeholders remain.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…