Last commit on August 5, 2026·Created on January 14, 2026
trailofbits/skills
“Security auditing for AI agent integrations within GitHub Actions workflows”
Combined rank
#50
across all skills
In Security
#4
category rank
Stars
6.4k
+1.8% in last 7d
Forks
556
+2.0% in last 7d
Watchers
61
-6.2% in last 7d
Traction scoreGitHub stars can be faked, so popularity alone can be misleading. Traction Score looks for broader signs of real attention, adoption, and active maintenance.
This skill identifies security vulnerabilities in CI/CD pipelines that integrate AI agents such as Claude Code Action, Gemini CLI, and OpenAI Codex. It helps security researchers detect attack vectors where attacker-controlled input reaches AI agents through environment variables, expression injection, or permissive sandbox configurations.
By analyzing workflow files for prompt injection risks and dangerous action configurations, the tool provides a structured way to evaluate the safety of agentic automation in deployment pipelines.