GitHub Actions Permission Scope Audit for Openclaw

A security-focused tool to detect and audit over-privileged GitHub Actions workflow tokens to enforce least-privilege access.

daniellummis
v1.0.0
Mar 8, 2026
0
786
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install github-actions-permission-scope-audit

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install github-actions-permission-scope-audit using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is GitHub Actions Permission Scope Audit?

The GitHub Actions Permission Scope Audit skill is designed to fortify your CI/CD pipeline security by analyzing workflow YAML files for permission drift. It helps developers and security engineers identify risky configurations where the GITHUB_TOKEN is granted excessive permissions, such as write access or broad scopes that could lead to repository compromise.

By integrating this tool into your Openclaw Skills library, you can automate the detection of dangerous patterns like the use of pull_request_target with write permissions or the absence of explicit permission policies. This ensures that every workflow in your repository adheres to modern security best practices without manual oversight.

GitHub Actions Permission Scope Audit Use Cases

  • Auditing existing repositories for GITHUB_TOKEN permission drift.
  • Enforcing a least-privilege security policy across all organization workflows.
  • Detecting risky pull_request_target triggers that have dangerous write access.
  • Automating security gates in CI to fail builds that contain over-privileged workflows.
  • Transitioning from legacy write-all permissions to fine-grained scopes.

How GitHub Actions Permission Scope Audit Works

  1. The skill identifies target GitHub Actions workflow files using a customizable file glob pattern.
  2. It parses the YAML structure of each workflow to extract the permissions and trigger blocks.
  3. A scoring engine evaluates the risk level based on detected patterns like write-all or missing explicit permission definitions.
  4. The skill ranks workflows by their risk score and flags those exceeding the defined critical threshold.
  5. A report is generated in text or JSON format, allowing for human review or automated CI/CD gating using Openclaw Skills scripts.

GitHub Actions Permission Scope Audit Setup

To get started with this skill, ensure you have bash and python3 installed in your environment. You can then run the audit script directly from your terminal:

# Run a basic audit report
WORKFLOW_GLOB='.github/workflows/*.yml' \
bash skills/github-actions-permission-scope-audit/scripts/permission-scope-audit.sh

# Run with JSON output and failure on critical findings
WORKFLOW_GLOB='.github/workflows/*.yml' \
OUTPUT_FORMAT=json \
FAIL_ON_CRITICAL=1 \
bash skills/github-actions-permission-scope-audit/scripts/permission-scope-audit.sh

GitHub Actions Permission Scope Audit Data Schema & Taxonomy

The skill processes workflow YAML files and generates structured reports based on the following metadata taxonomy:

Field Description
summary Aggregated statistics of audited workflows and detected risks.
ranked_workflows A list of workflows sorted by risk score.
critical_workflows A filtered list of workflows that triggered the fail gate.
score Numerical value representing the severity of permission drift.

GitHub Actions Permission Scope Audit Advanced Features

  • Customizable risk scoring via WARN_SCORE and CRITICAL_SCORE environment variables.
  • Granular filtering using regex patterns for workflow names, events, or specific permissions using Openclaw Skills parameters.
  • Seamless CI/CD integration using FAIL_ON_CRITICAL to block insecure code changes in pull requests.
  • Multi-format output support (JSON/Text) for integration with other automation tools.
  • Capability to toggle specific detection flags like FLAG_MISSING_PERMISSIONS or FLAG_WRITE_ALL for focused auditing.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Requires
Bins bashpython3
Github Stars: 0
forks: 0

Featured*