Securing GitHub Actions workflows - **name_fr:** Sécurisation des workflows GitHub Actions - **tl_en:** Harden GitHub Actions — SHA pinning, GITHUB_TOKEN permissions, script-injection prevention - **tl_fr:** Durcir GitHub Actions — épinglage SHA, permissions GITHUB_TOKEN, prévention de l'injection de scripts - **creator:** @mukul975 - **type:** Agent skill - **url:** https://github.com/mukul975/anthropic-cybersecurity-skills - **cat:** Security - **kws:** github actions, cicd, supply chain, sha pinning, github_token, secrets, devsecops - **license:** Apache-2.0 **Description EN:** Curated by Skill Harbor — a skill for hardening GitHub Actions workflows against supply chain attacks, credential theft and privilege escalation: pin actions to SHA digests, minimize GITHUB_TOKEN permissions, protect secrets, prevent script injection in workflow expressions (untrusted PR titles, branch names, commit messages), and require reviewers for workflow changes. The remediation companion to the supply-chain detection skill — pair them for audit-then-fix. By @mukul975, listed here with credit to its creator. Honest caveats: GitHub Actions only — other CI/CD platforms need their own platform guides; hardening changes workflow files, so changes must go through your normal code review; pinning to SHAs trades convenience for security and complicates action updates. Not verified. Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh. **Description FR:** Sélectionné par Skill Harbor — un skill pour durcir les workflows GitHub Actions contre les attaques supply chain, le vol d'identifiants et l'escalade de privilèges : épingler les actions aux digests SHA, minimiser les permissions GITHUB_TOKEN, protéger les secrets, prévenir l'injection de scripts dans les expressions de workflows (titres de PR, noms de branches, messages de commit non fiables), et exiger des relecteurs pour les changements de workflows. Le compagnon remédiation du skill de détection supply chain — combinez-les pour auditer puis corriger. Crédit : @mukul975. Bémols honnêtes : GitHub Actions uniquement — les autres plateformes CI/CD ont leurs propres guides ; le durcissement modifie les fichiers de workflows, donc les changements doivent passer par votre revue de code normale ; l'épinglage SHA échange la commodité contre la sécurité et complique les mises à jour d'actions. Non vérifié. Skill Harbor ne vérifie jamais le code, examinez-le vous-même avant usage. Découvert via skills.sh. **Install prompt EN:** ``` Prerequisites: a GitHub repository with Actions workflows you administer; review rights over workflow file changes Install "Securing GitHub Actions workflows" for me. Give my agent the skill for hardening GitHub Actions workflows — SHA pinning, GITHUB_TOKEN permissions, secret protection, script-injection prevention, reviewer requirements Repository: https://github.com/mukul975/anthropic-cybersecurity-skills/blob/main/skills/securing-github-actions-workflows/SKILL.md 1. Fetch the SKILL.md file for the mukul975-anthropic-cybersecurity-skills-securing-github-actions-workflows skill from the repository into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md and scripts for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "mukul975-anthropic-cybersecurity-skills-securing-github-actions-workflows". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. point the agent at the workflows to harden). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. Never ask me to paste secrets in chat — credentials go through the secure vault or environment variables. If anything looks off, stop and ask me. ``` **Install prompt FR:** ``` Prérequis : un dépôt GitHub avec des workflows Actions que vous administrez ; droits de revue sur les changements de fichiers de workflows Installe-moi « Sécurisation des workflows GitHub Actions ». Donne à mon agent le skill de durcissement des workflows GitHub Actions — épinglage SHA, permissions GITHUB_TOKEN, protection des secrets, prévention de l'injection de scripts, exigences de relecteurs Dépôt : https://github.com/mukul975/anthropic-cybersecurity-skills/blob/main/skills/securing-github-actions-workflows/SKILL.md 1. Récupère le fichier SKILL.md du skill mukul975-anthropic-cybersecurity-skills-securing-github-actions-workflows depuis le dépôt dans un dossier temporaire et résume en une ou deux phrases ce qu'il fait. 2. Contrôle de sécurité : examine le SKILL.md et les scripts pour tout contenu suspect (appels réseau inattendus, commandes shell, récolte d'identifiants). Ce dépôt ne doit contenir aucun secret dans le code ; les identifiants passent uniquement par le coffre sécurisé, les hôtes autorisés sont déclarés dans le SKILL.md. Vérifie que c'est bien le cas ; STOP sur le moindre signal d'alerte et préviens-moi. 3. Installe-le comme skill : copie SKILL.md et ses fichiers auxiliaires dans le répertoire des skills de l'agent, dans un dossier nommé « mukul975-anthropic-cybersecurity-skills-securing-github-actions-workflows ». 4. Vérifie sans aucun appel réseau : frontmatter valide, fichiers en place. 5. Indique ce qui a été installé, où, et ce qu'il me reste à faire moi-même (p. ex. indiquer à l'agent les workflows à durcir). GitHub est optionnel : si j'ai un compte GitHub ou la CLI gh, tu peux l'utiliser ; sinon l'accès public suffit. Ne jamais l'exiger sauf si c'est dans les prérequis ci-dessus. Règles : ne touche à rien en dehors du dossier temporaire et de la cible d'installation. Ne me demande jamais de coller des secrets dans le chat — les identifiants passent par le coffre sécurisé ou les variables d'environnement. Si quelque chose semble anormal, arrête-toi et demande-moi. ``` ---
Harden GitHub Actions — SHA pinning, GITHUB_TOKEN permissions, script-injection prevention - **tl_fr:** Durcir GitHub Actions — épinglage SHA, permissions GITHUB_TOKEN, prévention de l'injection de scripts - **creator:** @mukul975 - **type:** Agent skill - **url:** https://github.com/mukul975/anthropic-cybersecurity-skills - **cat:** Security - **kws:** github actions, cicd, supply chain, sha pinning, github_token, secrets, devsecops - **license:** Apache-2.0 **Description EN:** Curated by Skill Harbor — a skill for hardening GitHub Actions workflows against supply chain attacks, credential theft and privilege escalation: pin actions to SHA digests, minimize GITHUB_TOKEN permissions, protect secrets, prevent script injection in workflow expressions (untrusted PR titles, branch names, commit messages), and require reviewers for workflow changes. The remediation companion to the supply-chain detection skill — pair them for audit-then-fix. By @mukul975, listed here with credit to its creator. Honest caveats: GitHub Actions only — other CI/CD platforms need their own platform guides; hardening changes workflow files, so changes must go through your normal code review; pinning to SHAs trades convenience for security and complicates action updates. Not verified. Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh. **Description FR:** Sélectionné par Skill Harbor — un skill pour durcir les workflows GitHub Actions contre les attaques supply chain, le vol d'identifiants et l'escalade de privilèges : épingler les actions aux digests SHA, minimiser les permissions GITHUB_TOKEN, protéger les secrets, prévenir l'injection de scripts dans les expressions de workflows (titres de PR, noms de branches, messages de commit non fiables), et exiger des relecteurs pour les changements de workflows. Le compagnon remédiation du skill de détection supply chain — combinez-les pour auditer puis corriger. Crédit : @mukul975. Bémols honnêtes : GitHub Actions uniquement — les autres plateformes CI/CD ont leurs propres guides ; le durcissement modifie les fichiers de workflows, donc les changements doivent passer par votre revue de code normale ; l'épinglage SHA échange la commodité contre la sécurité et complique les mises à jour d'actions. Non vérifié. Skill Harbor ne vérifie jamais le code, examinez-le vous-même avant usage. Découvert via skills.sh. **Install prompt EN:** ``` Prerequisites: a GitHub repository with Actions workflows you administer; review rights over workflow file changes Install "Securing GitHub Actions workflows" for me. Give my agent the skill for hardening GitHub Actions workflows — SHA pinning, GITHUB_TOKEN permissions, secret protection, script-injection prevention, reviewer requirements Repository: https://github.com/mukul975/anthropic-cybersecurity-skills/blob/main/skills/securing-github-actions-workflows/SKILL.md 1. Fetch the SKILL.md file for the mukul975-anthropic-cybersecurity-skills-securing-github-actions-workflows skill from the repository into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md and scripts for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "mukul975-anthropic-cybersecurity-skills-securing-github-actions-workflows". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. point the agent at the workflows to harden). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. Never ask me to paste secrets in chat — credentials go through the secure vault or environment variables. If anything looks off, stop and ask me. ``` **Install prompt FR:** ``` Prérequis : un dépôt GitHub avec des workflows Actions que vous administrez ; droits de revue sur les changements de fichiers de workflows Installe-moi « Sécurisation des workflows GitHub Actions ». Donne à mon agent le skill de durcissement des workflows GitHub Actions — épinglage SHA, permissions GITHUB_TOKEN, protection des secrets, prévention de l'injection de scripts, exigences de relecteurs Dépôt : https://github.com/mukul975/anthropic-cybersecurity-skills/blob/main/skills/securing-github-actions-workflows/SKILL.md 1. Récupère le fichier SKILL.md du skill mukul975-anthropic-cybersecurity-skills-securing-github-actions-workflows depuis le dépôt dans un dossier temporaire et résume en une ou deux phrases ce qu'il fait. 2. Contrôle de sécurité : examine le SKILL.md et les scripts pour tout contenu suspect (appels réseau inattendus, commandes shell, récolte d'identifiants). Ce dépôt ne doit contenir aucun secret dans le code ; les identifiants passent uniquement par le coffre sécurisé, les hôtes autorisés sont déclarés dans le SKILL.md. Vérifie que c'est bien le cas ; STOP sur le moindre signal d'alerte et préviens-moi. 3. Installe-le comme skill : copie SKILL.md et ses fichiers auxiliaires dans le répertoire des skills de l'agent, dans un dossier nommé « mukul975-anthropic-cybersecurity-skills-securing-github-actions-workflows ». 4. Vérifie sans aucun appel réseau : frontmatter valide, fichiers en place. 5. Indique ce qui a été installé, où, et ce qu'il me reste à faire moi-même (p. ex. indiquer à l'agent les workflows à durcir). GitHub est optionnel : si j'ai un compte GitHub ou la CLI gh, tu peux l'utiliser ; sinon l'accès public suffit. Ne jamais l'exiger sauf si c'est dans les prérequis ci-dessus. Règles : ne touche à rien en dehors du dossier temporaire et de la cible d'installation. Ne me demande jamais de coller des secrets dans le chat — les identifiants passent par le coffre sécurisé ou les variables d'environnement. Si quelque chose semble anormal, arrête-toi et demande-moi. ``` ---
- What
- Harden GitHub Actions — SHA pinning, GITHUB_TOKEN permissions, script-injection prevention - **tl_fr:** Durcir GitHub Actions — épinglage SHA, permissions GITHUB_TOKEN, prévention de l'injection de scripts - **creator:** @mukul975 - **type:** Agent skill - **url:** https://github.com/mukul975/anthropic-cybersecurity-skills - **cat:** Security - **kws:** github actions, cicd, supply chain, sha pinning, github_token, secrets, devsecops - **license:** Apache-2.0 **Description EN:** Curated by Skill Harbor — a skill for hardening GitHub Actions workflows against supply chain attacks, credential theft and privilege escalation: pin actions to SHA digests, minimize GITHUB_TOKEN permissions, protect secrets, prevent script injection in workflow expressions (untrusted PR titles, branch names, commit messages), and require reviewers for workflow changes. The remediation companion to the supply-chain detection skill — pair them for audit-then-fix. By @mukul975, listed here with credit to its creator. Honest caveats: GitHub Actions only — other CI/CD platforms need their own platform guides; hardening changes workflow files, so changes must go through your normal code review; pinning to SHAs trades convenience for security and complicates action updates. Not verified. Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh. **Description FR:** Sélectionné par Skill Harbor — un skill pour durcir les workflows GitHub Actions contre les attaques supply chain, le vol d'identifiants et l'escalade de privilèges : épingler les actions aux digests SHA, minimiser les permissions GITHUB_TOKEN, protéger les secrets, prévenir l'injection de scripts dans les expressions de workflows (titres de PR, noms de branches, messages de commit non fiables), et exiger des relecteurs pour les changements de workflows. Le compagnon remédiation du skill de détection supply chain — combinez-les pour auditer puis corriger. Crédit : @mukul975. Bémols honnêtes : GitHub Actions uniquement — les autres plateformes CI/CD ont leurs propres guides ; le durcissement modifie les fichiers de workflows, donc les changements doivent passer par votre revue de code normale ; l'épinglage SHA échange la commodité contre la sécurité et complique les mises à jour d'actions. Non vérifié. Skill Harbor ne vérifie jamais le code, examinez-le vous-même avant usage. Découvert via skills.sh. **Install prompt EN:** ``` Prerequisites: a GitHub repository with Actions workflows you administer; review rights over workflow file changes Install "Securing GitHub Actions workflows" for me. Give my agent the skill for hardening GitHub Actions workflows — SHA pinning, GITHUB_TOKEN permissions, secret protection, script-injection prevention, reviewer requirements Repository: https://github.com/mukul975/anthropic-cybersecurity-skills/blob/main/skills/securing-github-actions-workflows/SKILL.md 1. Fetch the SKILL.md file for the mukul975-anthropic-cybersecurity-skills-securing-github-actions-workflows skill from the repository into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md and scripts for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "mukul975-anthropic-cybersecurity-skills-securing-github-actions-workflows". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. point the agent at the workflows to harden). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. Never ask me to paste secrets in chat — credentials go through the secure vault or environment variables. If anything looks off, stop and ask me. ``` **Install prompt FR:** ``` Prérequis : un dépôt GitHub avec des workflows Actions que vous administrez ; droits de revue sur les changements de fichiers de workflows Installe-moi « Sécurisation des workflows GitHub Actions ». Donne à mon agent le skill de durcissement des workflows GitHub Actions — épinglage SHA, permissions GITHUB_TOKEN, protection des secrets, prévention de l'injection de scripts, exigences de relecteurs Dépôt : https://github.com/mukul975/anthropic-cybersecurity-skills/blob/main/skills/securing-github-actions-workflows/SKILL.md 1. Récupère le fichier SKILL.md du skill mukul975-anthropic-cybersecurity-skills-securing-github-actions-workflows depuis le dépôt dans un dossier temporaire et résume en une ou deux phrases ce qu'il fait. 2. Contrôle de sécurité : examine le SKILL.md et les scripts pour tout contenu suspect (appels réseau inattendus, commandes shell, récolte d'identifiants). Ce dépôt ne doit contenir aucun secret dans le code ; les identifiants passent uniquement par le coffre sécurisé, les hôtes autorisés sont déclarés dans le SKILL.md. Vérifie que c'est bien le cas ; STOP sur le moindre signal d'alerte et préviens-moi. 3. Installe-le comme skill : copie SKILL.md et ses fichiers auxiliaires dans le répertoire des skills de l'agent, dans un dossier nommé « mukul975-anthropic-cybersecurity-skills-securing-github-actions-workflows ». 4. Vérifie sans aucun appel réseau : frontmatter valide, fichiers en place. 5. Indique ce qui a été installé, où, et ce qu'il me reste à faire moi-même (p. ex. indiquer à l'agent les workflows à durcir). GitHub est optionnel : si j'ai un compte GitHub ou la CLI gh, tu peux l'utiliser ; sinon l'accès public suffit. Ne jamais l'exiger sauf si c'est dans les prérequis ci-dessus. Règles : ne touche à rien en dehors du dossier temporaire et de la cible d'installation. Ne me demande jamais de coller des secrets dans le chat — les identifiants passent par le coffre sécurisé ou les variables d'environnement. Si quelque chose semble anormal, arrête-toi et demande-moi. ``` ---
- Cost
- Free
- Needs
- a GitHub repository with Actions workflows you administer; review rights over workflow file changes
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor — a skill for hardening GitHub Actions workflows against supply chain attacks, credential theft and privilege escalation: pin actions to SHA digests, minimize GITHUB_TOKEN permissions, protect secrets, prevent script injection in workflow expressions (untrusted PR titles, branch names, commit messages), and require reviewers for workflow changes. The remediation companion to the supply-chain detection skill — pair them for audit-then-fix. By @mukul975, listed here with credit to its creator. Honest caveats: GitHub Actions only — other CI/CD platforms need their own platform guides; hardening changes workflow files, so changes must go through your normal code review; pinning to SHAs trades convenience for security and complicates action updates. Not verified. Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh.
Version:
Install
Prerequisites: a GitHub repository with Actions workflows you administer; review rights over workflow file changes Install "Securing GitHub Actions workflows" for me. Give my agent the skill for hardening GitHub Actions workflows — SHA pinning, GITHUB_TOKEN permissions, secret protection, script-injection prevention, reviewer requirements Repository: https://github.com/mukul975/anthropic-cybersecurity-skills/blob/main/skills/securing-github-actions-workflows/SKILL.md 1. Fetch the SKILL.md file for the mukul975-anthropic-cybersecurity-skills-securing-github-actions-workflows skill from the repository into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md and scripts for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "mukul975-anthropic-cybersecurity-skills-securing-github-actions-workflows". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. point the agent at the workflows to harden). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. Never ask me to paste secrets in chat — credentials go through the secure vault or environment variables. If anything looks off, stop and ask me.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.