Skip to main content

Actions Warden

Read-only auditor for risky or injected GitHub Actions workflow config.

Current release: 0.1.3

After the 2026 wave of repository-theft attacks, a common post-compromise move is: steal a token, then inject or tamper with a repo's .github/workflows/ so CI exfiltrates secrets or runs attacker code. Actions Warden scans those workflow files for the patterns that enable it.

It does not execute workflows, contact GitHub, modify files, or prove a pipeline is safe. No telemetry, no data storage, no automatic remediation — alerts only.

Part of the Dragon Lady open security kit used alongside package/host scanners during the August 2026 npm/keyv (ChainDrop / Shai-Hulud) emergency tooling updates: when tokens may have been stolen, also audit CI workflows.

Install

pipx install actions-warden
# or
pip install actions-warden
# upgrade:
pipx upgrade actions-warden
# or: pip install -U actions-warden

Python 3.9+. No runtime dependencies.

Usage

actions-warden --version
actions-warden /path/to/repo
actions-warden /path/to/repo --json
actions-warden /path/to/repo --report report.json

It scans .github/workflows/*.yml|*.yaml and composite action.yml|action.yaml files. You can also point it at a single workflow file.

Exit codes:

  • 0: no blocking workflow risks found
  • 1: usage or runtime error
  • 2: blocking workflow risks found (suitable as a CI gate)

What It Flags

Rule Severity What it catches
secret-exfiltration critical a secret reference alongside an outbound network command
untrusted-input-injection high attacker-controllable github.event.* / head_ref interpolated into the workflow (shell injection in run steps)
remote-code-in-run high a downloaded script piped straight into a shell
pull-request-target-head-checkout high pull_request_target running with secrets while checking out PR-controlled code ("pwn request")
checkout-unsafe-pr-opt-out high actions/checkout explicitly setting allow-unsafe-pr-checkout on privileged PR-adjacent triggers
self-hosted-on-untrusted medium self-hosted runner reachable by external pull requests
permissions-write-all medium write-all token permissions
oidc-with-write medium OIDC id-token: write combined with contents: write
deployment-trigger-review medium workflows triggered by deployment / deployment_status that need GitHub workflow execution protections reviewed
deployment-trigger-privileged high deployment-triggered workflows that also reference secrets, OIDC, or write permissions
unpinned-action low third-party action pinned to a mutable tag/branch instead of a commit SHA

The rules are conservative. A finding means "review this workflow," not "this repo is compromised."

GitHub announced safer actions/checkout@v7 defaults for common pull_request_target pwn-request patterns on 2026-06-18, with supported major tag backports planned for 2026-07-16. Workflows pinned to a minor, patch, or full SHA need an explicit upgrade to receive that behavior, and any allow-unsafe-pr-checkout opt-out should be treated as a deliberate high-risk review item.

GitHub's workflow execution protections public preview also lets organizations restrict which actors and event types can trigger workflows. Treat deployment / deployment_status workflows as review items, and treat deployment-triggered workflows that use secrets, OIDC, or write permissions as blocked until the repository or organization restricts that trigger.

Why text-based, not YAML-parsed

A hostile workflow can be written to parse in surprising ways. Actions Warden inspects what is actually on disk rather than a parser's normalized view, and stays dependency-free. The tradeoff is coarser context: some file_all rules flag co-occurrence within a file rather than within a single job.

Scope Limits

This is a narrow CI/CD config scanner. It does not scan dependencies or packages (see a dependency/supply-chain scanner for that), does not resolve reusable or remote workflows, and will not catch every possible injection or obfuscated payload.

Metadata

Release files for actions-warden 0.1.3

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for actions-warden 0.1.3
File Size Uploaded
actions_warden-0.1.3.tar.gz 14.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for actions-warden 0.1.3
File Interpreter ABI Platform
actions_warden-0.1.3-py3-none-any.whl Python 3 none any Details

Total release size: 25.8 kB

Release files / actions_warden-0.1.3.tar.gz

Download URL actions_warden-0.1.3.tar.gz
Size 14.0 kB
Tags Source
SHA-256 checksum
How to use checksums
1b5adfaaf0d242eac0c0eaaf39764fe38b1875c9c73cfac4fb7040c8b4b83cb7
BLAKE2b-256 checksum
How to use checksums
65e4d2052f5470d5e864f7daa74bea5e8fd2ee44661877f3f1575db7341fe993
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.13

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 5, 2026.

Transparency log

Release files / actions_warden-0.1.3-py3-none-any.whl

Download URL actions_warden-0.1.3-py3-none-any.whl
Size 11.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
0cd4f4639c23704e6eca9a4fbec55afb73b849fe4d03479a5155246f1ee1add4
BLAKE2b-256 checksum
How to use checksums
055285f2d0f51fbab8a2c3d00fa18b9707035580db8b48bd60dbf04bbfa275c6
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.13

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 5, 2026.

Transparency log

Release history Release notifications | RSS feed

0.1.4

2 release files

This release

0.1.3 This release

2 release files

0.1.2

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page