GitHub Actions Self-Hosted Risk Audit for Openclaw

A specialized security auditing tool for identifying high-risk configurations in GitHub Actions workflows utilizing self-hosted runners.

daniellummis
v1.0.0
Mar 8, 2026
0
824
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install github-actions-self-hosted-risk-audit

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install github-actions-self-hosted-risk-audit using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is GitHub Actions Self-Hosted Risk Audit?

The GitHub Actions Self-Hosted Risk Audit is a vital security tool designed to protect infrastructure from common CI/CD vulnerabilities. It specifically targets workflows running on self-hosted runners, which can be susceptible to malicious code execution if not properly hardened. This skill provides automated scanning for dangerous triggers like pull_request_target and ensures that sensitive credentials are not unnecessarily persisted during the build process.

By integrating this audit into your Openclaw Skills library, you can proactively identify and remediate security gaps before they are exploited in production environments. It empowers developers to maintain high security standards without manual oversight, making it an essential addition to any robust DevSecOps strategy.

GitHub Actions Self-Hosted Risk Audit Use Cases

  • Auditing existing GitHub Actions workflows for compliance with security best practices.
  • Preventing unauthorized access to internal infrastructure via self-hosted runner vulnerabilities.
  • Identifying workflows that use risky triggers like pull_request_target or issue_comment.
  • Hardening CI/CD pipelines by enforcing credential persistence policies.
  • Implementing a security fail-gate in development environments to block high-risk workflow commits.

How GitHub Actions Self-Hosted Risk Audit Works

  1. The skill initializes by scanning the specified directory for workflow YAML files using a configurable glob pattern.
  2. It parses each workflow to detect the use of self-hosted runner labels.
  3. A scoring engine evaluates the workflow against specific risk factors, such as untrusted trigger types and broad runner selection.
  4. It checks for specific hardening measures, including write-capable permissions and the persist-credentials setting in checkout actions.
  5. The skill generates a comprehensive report in text or JSON format, assigning a risk score to each workflow.
  6. If configured, the process exits with a failure code to prevent further progression in a CI/CD pipeline if critical risks are found.

GitHub Actions Self-Hosted Risk Audit Setup

Ensure that bash and python3 are available in your environment. You can run the audit against your workflows using the following command structure within your Openclaw Skills setup:

# Run a basic text report against local workflows
WORKFLOW_GLOB='.github/workflows/*.yml' \
WARN_SCORE=4 \
CRITICAL_SCORE=8 \
bash skills/github-actions-self-hosted-risk-audit/scripts/self-hosted-risk-audit.sh

For CI integration with a fail gate, use:

WORKFLOW_GLOB='.github/workflows/*.y*ml' \
OUTPUT_FORMAT=json \
FAIL_ON_CRITICAL=1 \
bash skills/github-actions-self-hosted-risk-audit/scripts/self-hosted-risk-audit.sh

GitHub Actions Self-Hosted Risk Audit Data Schema & Taxonomy

The skill processes workflow files and produces structured output. The following inputs and metadata are used to organize the audit data:

Parameter Description Default Value
WORKFLOW_GLOB Path pattern to find workflow files .github/workflows/.yml
TOP_N Number of flagged workflows to display 20
OUTPUT_FORMAT The format of the resulting report text
WARN_SCORE Threshold for flagging a warning 4
CRITICAL_SCORE Threshold for flagging a critical risk 8
FAIL_ON_CRITICAL Whether to exit with error code 1 on risks 0

The JSON output includes a summary object and an array of flagged workflows with their associated risk scores and specific violation details.

GitHub Actions Self-Hosted Risk Audit Advanced Features

  • Customizable risk scoring thresholds for both warnings and critical alerts to match organizational risk appetite.
  • Support for JSON output for seamless integration with other Openclaw Skills or external monitoring dashboards.
  • Regex-based inclusion and exclusion patterns (WORKFLOW_FILE_MATCH / WORKFLOW_FILE_EXCLUDE) for fine-grained workflow selection.
  • Integrated CI fail-gate capability to enforce security standards automatically during the commit or PR process.
  • Capability to run against bundled fixtures to verify audit logic and expected behavior.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Requires
Bins bashpython3
Github Stars: 0
forks: 0

Featured*