maxtac-supply-chain-cicd-release-takeover

Analyze CI/CD release workflows for security vulnerabilities from untrusted input to high-trust authority.

12|Updated Jun 1, 2026
One-click install
npx skills add https://github.com/philo-groves/MaxTAC --skill maxtac-supply-chain-cicd-release-takeover
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: maxtac-supply-chain-cicd-release-takeover
Source: https://github.com/philo-groves/MaxTAC/tree/main/plugins/maxtac-supply-chains/skills/maxtac-supply-chain-cicd-release-takeover
Command: npx skills add https://github.com/philo-groves/MaxTAC --skill maxtac-supply-chain-cicd-release-takeover

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) components.

What problem does it solve?

This Skill identifies potential security vulnerabilities in CI/CD workflows, particularly focusing on advanced CI/CD, workflow, runner, cache, OIDC, release, publishing, signing, artifact promotion, or deployment takeover analysis.

Core Features & Use Cases

  • CI/CD Workflow Analysis: Trace whether untrusted CI input can reach trusted release, signing, publishing, or deployment authority.
  • High-Risk Pattern Identification: Detect patterns such as mutable action refs, compromised third-party actions, and OIDC federation issues.
  • Exploit Sequence Analysis: Understand the sequence of events leading to a potential release takeover.
  • Controls and Counterevidence: Evaluate branch protection, environment approvals, and artifact verification.

Quick Start

Use the maxtac-supply-chain-cicd-release-takeover skill to analyze the CI/CD release workflow for potential security vulnerabilities.

Frequently Asked Questions about maxtac-supply-chain-cicd-release-takeover

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is a CI/CD release takeover vulnerability in a supply chain?

A CI/CD release takeover vulnerability occurs when untrusted workflow input reaches trusted release, signing, or deployment authority. This analysis traces compromise paths through triggers, jobs, dependencies, artifacts, caches, environments, tokens, and external services.

How do I analyze my CI/CD workflow for supply chain security risks?

To analyze CI/CD workflows for supply chain security, trace untrusted CI input paths to high-trust authority. This skill evaluates workflow triggers, runner labels, OIDC federation, artifact promotion, and deployment sequences to detect potential compromise exploit paths.

Can I detect compromised third-party actions and mutable action refs in my pipeline?

Yes, you can detect high-risk patterns like mutable action refs, compromised third-party actions, and OIDC federation issues. The analysis evaluates branch protection, environment approvals, and artifact verification as controls and counterevidence against release takeover.

Does this supply chain analysis require the MaxTAC CI/CD Release Takeover tool?

Yes, this supply chain analysis requires the MaxTAC CI/CD Release Takeover tool to evaluate advanced CI/CD workflows. It focuses on runner, cache, OIDC, publishing, signing, artifact promotion, and deployment takeover analysis.

What controls are evaluated to prevent CI/CD release takeover?

Controls evaluated to prevent CI/CD release takeover include branch protection, environment approvals, and artifact verification. The analysis assesses these counterevidence mechanisms against exploit sequences involving untrusted inputs reaching signing or deployment authority.