风险评分

94/100 (Very Low)

OpenClaw: benign
VirusTotal: benign
StaticScan: unknown

GitHub Actions Secret Exposure Audit

作者: Daniel Lummis
Slug:github-actions-secret-exposure-audit
版本:1.0.0
更新时间:2026-03-08 07:08:03
风险信息

OpenClaw: benign

查看 OpenClaw 分析摘要(前 200 字预览)
The skill's code, instructions, and requirements are consistent with an offline static audit of GitHub Actions workflow YAML files and do not request unrelated credentials or perform network/exfiltrat...

[内容已截断]

VirusTotal: benign VT 报告

静态扫描: unknown

README

README 未提供

文件列表

无文件信息

下载
下载官方 ZIP
原始 JSON 数据
{
    "latestVersion": {
        "_creationTime": 1772924873942,
        "_id": "k972mft00vav3hc1nerzwc75hd82fn02",
        "changelog": "Initial release with auditing features for GitHub Actions workflows:\n\n- Scans workflow YAML files for secret exposure risks.\n- Flags usage of secrets in pull_request_target, secret echo commands, and secrets passed to unpinned actions.\n- Detects hardcoded credentials in workflow config.\n- Supports both text and JSON output formats.\n- Configurable scoring, file matching, and CI fail gate for critical findings.",
        "changelogSource": "auto",
        "createdAt": 1772924873942,
        "parsed": {
            "clawdis": {
                "requires": {
                    "bins": [
                        "bash",
                        "python3"
                    ]
                }
            }
        },
        "version": "1.0.0"
    },
    "owner": {
        "_creationTime": 0,
        "_id": "publishers:missing",
        "displayName": "Daniel Lummis",
        "handle": "daniellummis",
        "image": "https:\/\/avatars.githubusercontent.com\/u\/65238171?v=4",
        "kind": "user",
        "linkedUserId": "kn74qp31gs45fmt9eg7jbc4r6n828jdj"
    },
    "ownerHandle": "daniellummis",
    "skill": {
        "_creationTime": 1772924873942,
        "_id": "kd722hm7gv35wvch13a931v8h182fphf",
        "badges": [],
        "createdAt": 1772924873942,
        "displayName": "GitHub Actions Secret Exposure Audit",
        "latestVersionId": "k972mft00vav3hc1nerzwc75hd82fn02",
        "ownerUserId": "kn74qp31gs45fmt9eg7jbc4r6n828jdj",
        "slug": "github-actions-secret-exposure-audit",
        "stats": {
            "comments": 0,
            "downloads": 167,
            "installsAllTime": 1,
            "installsCurrent": 1,
            "stars": 0,
            "versions": 1
        },
        "summary": "Audit GitHub Actions workflow files for secret exposure risks like pull_request_target secret usage, secret echo commands, and unpinned action secret passing.",
        "tags": {
            "latest": "k972mft00vav3hc1nerzwc75hd82fn02"
        },
        "updatedAt": 1772924883584
    }
}