A specialized security auditing tool for identifying high-risk configurations in GitHub Actions workflows utilizing self-hosted runners.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install github-actions-self-hosted-risk-audit
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install github-actions-self-hosted-risk-audit using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
The GitHub Actions Self-Hosted Risk Audit is a vital security tool designed to protect infrastructure from common CI/CD vulnerabilities. It specifically targets workflows running on self-hosted runners, which can be susceptible to malicious code execution if not properly hardened. This skill provides automated scanning for dangerous triggers like pull_request_target and ensures that sensitive credentials are not unnecessarily persisted during the build process.
By integrating this audit into your Openclaw Skills library, you can proactively identify and remediate security gaps before they are exploited in production environments. It empowers developers to maintain high security standards without manual oversight, making it an essential addition to any robust DevSecOps strategy.
Ensure that bash and python3 are available in your environment. You can run the audit against your workflows using the following command structure within your Openclaw Skills setup:
# Run a basic text report against local workflows
WORKFLOW_GLOB='.github/workflows/*.yml' \
WARN_SCORE=4 \
CRITICAL_SCORE=8 \
bash skills/github-actions-self-hosted-risk-audit/scripts/self-hosted-risk-audit.sh
For CI integration with a fail gate, use:
WORKFLOW_GLOB='.github/workflows/*.y*ml' \
OUTPUT_FORMAT=json \
FAIL_ON_CRITICAL=1 \
bash skills/github-actions-self-hosted-risk-audit/scripts/self-hosted-risk-audit.sh
The skill processes workflow files and produces structured output. The following inputs and metadata are used to organize the audit data:
| Parameter | Description | Default Value |
|---|---|---|
| WORKFLOW_GLOB | Path pattern to find workflow files | .github/workflows/.yml |
| TOP_N | Number of flagged workflows to display | 20 |
| OUTPUT_FORMAT | The format of the resulting report | text |
| WARN_SCORE | Threshold for flagging a warning | 4 |
| CRITICAL_SCORE | Threshold for flagging a critical risk | 8 |
| FAIL_ON_CRITICAL | Whether to exit with error code 1 on risks | 0 |
The JSON output includes a summary object and an array of flagged workflows with their associated risk scores and specific violation details.
Loading
An automated auditing tool to identify and mitigate secret exposure risks within GitHub Actions workflow configurations.

Analyze and compare GitHub Actions runtime metrics to detect performance regressions and optimize CI costs.

A diagnostic tool to identify GitHub Actions workflows that have missed their expected execution cadence.

Analyze GitHub Actions run history to identify and quantify the cost of flaky fail-then-success retry patterns.

Audit GitHub Actions rerun debt to identify and eliminate commit-level CI inefficiencies.

Identify and rank flaky GitHub Actions steps by analyzing success and failure outcomes across multiple workflow runs.








































