スキル監査レポート
harden-github-actions 監査レポート.
Harden GitHub Actions CI/CD workflows for supply-chain security — SHA-pin actions, least-privilege token permissions, verified toolchain installs, OpenSSF Scorecard, and SLSA provenance. Use when adding or auditing GitHub Actions workflows, before making a repository public, when a supply-chain review flags CI gaps, or when standardizing CI hardening across GitHub projects. GitHub-specific by design — GitLab CI and Forgejo Actions are out of scope.
OpenAgentSkill Trust Score
OpenAgentSkill Trust Score
Trust Score は、インストール前に候補に入れる安全性を Agent が判断する助けになります。
GitHub 採用度
失敗30
GitHub スター 14
スター/フォーク活動
失敗32
スター 14、フォーク 0; 現在のメタデータでは Issue 活動を利用できません
最近のメンテナンス
合格100
最終プッシュから 1 日
ライセンスの明確さ
合格86
MIT
README/SKILL.md の完全性
合格86
メタデータには十分な利用・ワークフロー文脈があります
依存関係/ランタイムのリスク
失敗36
command execution surface, credential or environment access
インストール可否
合格92
npx skills add jrjsmrtn/project-orchestration-skills --skill harden-github-actions
インストールコマンドの安全性
合格92
標準パッケージまたはランタイムのインストールパス
権限範囲
失敗22
secrets or environment access, shell or command execution
リポジトリ根拠
合格86
https://github.com/jrjsmrtn/project-orchestration-skills/tree/main/skills/harden-github-actions
レビュー状況
合格88
AI レビューデータを利用できます
Agent 検証結果
情報54
Agent の成果データはまだありません
チェック
インストールと採用のレビュー
インストール経路
92
npx skills add jrjsmrtn/project-orchestration-skills --skill harden-github-actions
リポジトリ
88
https://github.com/jrjsmrtn/project-orchestration-skills/tree/main/skills/harden-github-actions
ライセンス
86
MIT
メンテナンス
100
最終プッシュから 1 日
AI レビュー
88
Approved with no listed issues
README/SKILL.md の完全性
86
Usable description available
依存関係リスク
36
command execution surface, credential or environment access
インストールコマンドの安全性
92
標準パッケージまたはランタイムのインストールパス
権限範囲
22
secrets or environment access, shell or command execution
スター/フォーク活動
32
スター 14、フォーク 0; 現在のメタデータでは Issue 活動を利用できません
採用度
42
GitHub スター 14
警告
- Dependency or permission surface needs review
- Permission surface may require sandboxing
- Low GitHub adoption signal
- Quality score needs review
- Permission surface needs review: secrets or environment access, shell or command execution
- GitHub adoption: 14 GitHub stars
- Stars/forks activity: 14 stars, 0 forks; issue activity unavailable in current metadata
- Dependency/runtime risk: command execution surface, credential or environment access
- Permission surface: secrets or environment access, shell or command execution
方法
このレポートは公開メタデータ、AI レビュー、リポジトリの鮮度、インストール準備、OpenAgentSkill イベント、品質スコア、信頼チェック、Agent セーフティゲートを統合します。完全なソースコード監査ではありません。
近い選択肢を比較
次に監査する関連スキル
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
16K スター · 監査レポート
Maigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
33K スター · 監査レポート
Nuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
29K スター · 監査レポート