A security-focused tool to detect and audit over-privileged GitHub Actions workflow tokens to enforce least-privilege access.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install github-actions-permission-scope-audit
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install github-actions-permission-scope-audit using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
The GitHub Actions Permission Scope Audit skill is designed to fortify your CI/CD pipeline security by analyzing workflow YAML files for permission drift. It helps developers and security engineers identify risky configurations where the GITHUB_TOKEN is granted excessive permissions, such as write access or broad scopes that could lead to repository compromise.
By integrating this tool into your Openclaw Skills library, you can automate the detection of dangerous patterns like the use of pull_request_target with write permissions or the absence of explicit permission policies. This ensures that every workflow in your repository adheres to modern security best practices without manual oversight.
To get started with this skill, ensure you have bash and python3 installed in your environment. You can then run the audit script directly from your terminal:
# Run a basic audit report
WORKFLOW_GLOB='.github/workflows/*.yml' \
bash skills/github-actions-permission-scope-audit/scripts/permission-scope-audit.sh
# Run with JSON output and failure on critical findings
WORKFLOW_GLOB='.github/workflows/*.yml' \
OUTPUT_FORMAT=json \
FAIL_ON_CRITICAL=1 \
bash skills/github-actions-permission-scope-audit/scripts/permission-scope-audit.sh
The skill processes workflow YAML files and generates structured reports based on the following metadata taxonomy:
| Field | Description |
|---|---|
| summary | Aggregated statistics of audited workflows and detected risks. |
| ranked_workflows | A list of workflows sorted by risk score. |
| critical_workflows | A filtered list of workflows that triggered the fail gate. |
| score | Numerical value representing the severity of permission drift. |
Loading
A security auditing tool for GitHub Actions that identifies OIDC misconfigurations and risky cloud authentication patterns.

A diagnostic tool for auditing GitHub merge queue workflows using failure rates, queue latency, and stale-success risk scoring.

A diagnostic tool to detect and audit manual trigger reliance in GitHub Actions workflows to improve automation and pipeline reliability.

A diagnostic tool that scores the reliability of GitHub Actions workflows on protected branches to detect silent delivery degradation.

A diagnostic tool to score and flag unreliable GitHub Actions workflows used in pull request and merge queue gates.

Identify and visualize GitHub Actions queue wait hotspots from run metadata to resolve CI bottlenecks before they stall development merges.








































