sc-ci-cd

Automate CI/CD pipeline security assessments across GitHub Actions and GitLab CI.

56|5|Updated Apr 8, 2026
One-click install
npx skills add https://github.com/ersinkoc/security-check --skill sc-ci-cd
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: sc-ci-cd
Source: https://github.com/ersinkoc/security-check/tree/main/skills/sc-ci-cd
Command: npx skills add https://github.com/ersinkoc/security-check --skill sc-ci-cd

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

CI/CD pipelines are a common attack surface; this Skill automates security checks across GitHub Actions, GitLab CI, and general pipeline configurations to identify misconfigurations and leakage risks.

Core Features & Use Cases

  • Detects GitHub Actions expression injection, untrusted actions, and secret exposure in logs.
  • Flags PR target misconfigurations, artifact poisoning risks, and cross-platform pipeline security gaps.
  • Use Case: A security engineer runs this skill to quickly audit all workflows in a repository and generate a prioritized remediation plan.

Quick Start

Run the sc-ci-cd scanner on your repository to identify GitHub Actions and GitLab CI security issues.

Frequently Asked Questions about sc-ci-cd

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I scan GitHub Actions workflows for expression injection and secret exposure?

To scan GitHub Actions workflows for expression injection and secret exposure, run this Skill on your repository to automate security checks and identify misconfigurations, untrusted actions, and leakage risks across your pipeline configurations.

What is artifact poisoning in CI/CD pipelines and how do I detect it?

Artifact poisoning in CI/CD pipelines occurs when build outputs are tampered with during the process. You can detect it by automating pipeline security assessments to flag artifact poisoning risks, PR target misconfigurations, and cross-platform security gaps.

Does this CI/CD security scanner work with GitLab CI configurations as well as GitHub Actions?

Yes, this CI/CD security scanner works with GitLab CI configurations as well as GitHub Actions. It automates security assessments across both platforms to identify misconfigurations, untrusted actions, and multi-repo pipeline risks.

What is the best way to audit all workflows in a repository and generate a remediation plan?

The best way to audit repository workflows and generate a remediation plan is to run an automated CI/CD security assessment. This Skill detects vulnerabilities, classifies severity, and references a centralized security checklist for prioritized remediation guidance.

How are detected CI/CD vulnerabilities classified and what remediation guidance is provided?

Detected CI/CD vulnerabilities are classified by severity and include specific remediation guidance. The Skill meets requirements for detection patterns and severity classification while referencing a centralized cicd-security-checklist located in references.

Can I check for multi-repo pipeline risks and untrusted actions across my DevOps pipelines?

Yes, you can check for multi-repo pipeline risks and untrusted actions across your DevOps pipelines. The Skill automates security checks to identify these risks along with expression injection, secret exposure in logs, and PR target misconfigurations.