{"slug":"github-github-actions-hardening","source_name":"github/github-actions-hardening","name":"Github/Github Actions Hardening","description":"Security hardening reviewer for GitHub Actions workflow files (.github/workflows/*.yml). Reasons about the Actions threat model that pattern matchers and general code linters miss — untrusted-input script injection, privileged triggers running fork code, mutable action references, and over-scoped tokens. Use this skill when asked to review, audit, harden, or secure a GitHub Actions workflow, when writing a new workflow, or for any request like \"is this workflow safe?\", \"review my CI for security","version":1,"lift":{"pass_rate_delta_pts":27.27,"pass_rate_pct":95.5,"total_cases":22,"passed_cases":21,"tokens_delta_pct":100.2,"turns_delta_pct":0,"verdict":"mixed","benchmark_model":"gemini-3.6-flash","grading_method":"judged","completed_at":"2026-08-02T20:31:21.248367+00:00"},"skill_score":0.9545,"benchmark_models":[{"model":"gemini-3.6-flash","headline":true,"delta_pts":27.27,"with_pass_pct":95.5,"without_pass_pct":68.2,"tokens_delta_pct":100.2,"turns_delta_pct":0,"total_cases":22,"cases_aggregated":22,"verdict":"mixed","never_hurt":false,"completed_at":"2026-08-02T20:31:21.248367+00:00","run_id":"d764d6c7-56d4-4605-9c30-7ef0d819ee8e","version_number":1,"is_latest_version":true,"gate":null}],"trust":{"skill_safety":"passed","safety_status":"clean","intent_verdict":"safe","content_status":"clean","indexable":true},"license":"MIT","install_count":0,"manifest_hash":"bf6244d0a436ac879994eb7fea53f2e8e97fdfefd478f850cc42986cf3fd0372","raw_url":"https://app.decimal.ai/s/github-github-actions-hardening/SKILL.md","scorecard_url":"https://app.decimal.ai/skills/github-github-actions-hardening"}