Skip to main content

Actions Warden

Read-only auditor for risky or injected GitHub Actions workflow config.

Current release: 0.1.4

After the 2026 wave of repository-theft attacks, a common post-compromise move is: steal a token, then inject or tamper with a repo's .github/workflows/ so CI exfiltrates secrets or runs attacker code. Actions Warden scans those workflow files for the patterns that enable it.

It does not execute workflows, contact GitHub, modify files, or prove a pipeline is safe. No telemetry, no data storage, no automatic remediation — alerts only.

Part of the Dragon Lady open security kit used alongside package/host scanners during the August 2026 npm/keyv (ChainDrop / Shai-Hulud) emergency tooling updates: when tokens may have been stolen, also audit CI workflows.

Install

pipx install actions-warden
# or
pip install actions-warden
# upgrade:
pipx upgrade actions-warden
# or: pip install -U actions-warden

Python 3.9+. No runtime dependencies.

Usage

actions-warden --version
actions-warden /path/to/repo
actions-warden /path/to/repo --json
actions-warden /path/to/repo --report report.json

It scans .github/workflows/*.yml|*.yaml and composite action.yml|action.yaml files. You can also point it at a single workflow file.

Exit codes:

  • 0: no blocking workflow risks found
  • 1: usage or runtime error
  • 2: blocking workflow risks found (suitable as a CI gate)

What It Flags

Rule Severity What it catches
secret-exfiltration critical a secret reference alongside an outbound network command
untrusted-input-injection high attacker-controllable github.event.* / head_ref interpolated into the workflow (shell injection in run steps)
remote-code-in-run high a downloaded script piped straight into a shell
pull-request-target-head-checkout high pull_request_target running with secrets while checking out PR-controlled code ("pwn request")
checkout-unsafe-pr-opt-out high actions/checkout explicitly setting allow-unsafe-pr-checkout on privileged PR-adjacent triggers
self-hosted-on-untrusted medium self-hosted runner reachable by external pull requests
permissions-write-all medium write-all token permissions
oidc-with-write medium OIDC id-token: write combined with contents: write
deployment-trigger-review medium workflows triggered by deployment / deployment_status that need GitHub workflow execution protections reviewed
deployment-trigger-privileged high deployment-triggered workflows that also reference secrets, OIDC, or write permissions
unpinned-action low third-party action pinned to a mutable tag/branch instead of a commit SHA
hijacked-actions-cool-tag critical actions-cool/issues-helper or actions-cool/maintain-one-comment on a tag, branch, or the known hijacked commit. Stop using the tag. Do not revoke tokens until the monitor and wiper are understood
memtensor-sckit-stage0 critical workflow text contains both sckit and stage0. Treat the runner and publish tokens as exposed. Do not run the step. Notify-only

The rules are conservative. A finding means "review this workflow," not "this repo is compromised."

GitHub announced safer actions/checkout@v7 defaults for common pull_request_target pwn-request patterns on 2026-06-18, with supported major tag backports planned for 2026-07-16. Workflows pinned to a minor, patch, or full SHA need an explicit upgrade to receive that behavior, and any allow-unsafe-pr-checkout opt-out should be treated as a deliberate high-risk review item.

GitHub's workflow execution protections public preview also lets organizations restrict which actors and event types can trigger workflows. Treat deployment / deployment_status workflows as review items, and treat deployment-triggered workflows that use secrets, OIDC, or write permissions as blocked until the repository or organization restricts that trigger.

Why text-based, not YAML-parsed

A hostile workflow can be written to parse in surprising ways. Actions Warden inspects what is actually on disk rather than a parser's normalized view, and stays dependency-free. The tradeoff is coarser context: some file_all rules flag co-occurrence within a file rather than within a single job.

Scope Limits

This is a narrow CI/CD config scanner. It does not scan dependencies or packages (see a dependency/supply-chain scanner for that), does not resolve reusable or remote workflows, and will not catch every possible injection or obfuscated payload.

Metadata

Release files for actions-warden 0.1.4

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for actions-warden 0.1.4
File Size Uploaded
actions_warden-0.1.4.tar.gz 15.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for actions-warden 0.1.4
File Interpreter ABI Platform
actions_warden-0.1.4-py3-none-any.whl Python 3 none any Details

Total release size: 28.0 kB

Release files / actions_warden-0.1.4.tar.gz

Download URL actions_warden-0.1.4.tar.gz
Size 15.3 kB
Tags Source
SHA-256 checksum
How to use checksums
6975711acd1977bb2c52de344413d17ba8d83b2216a1fed4b0f15492b76dc293
BLAKE2b-256 checksum
How to use checksums
03976719af91f5c59a76c0faf28565992aad47d1182ebf5bae6f02ac491d71a3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.13

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.

Transparency log

Release files / actions_warden-0.1.4-py3-none-any.whl

Download URL actions_warden-0.1.4-py3-none-any.whl
Size 12.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
43e590e46d69b9bfc531ae50d651095c0e551d568c2fd34fbec6c22e18b42bea
BLAKE2b-256 checksum
How to use checksums
35dcb6be6c189ba07b66dcfca502f39f974dec1f83c500bf7e67c7af7f10b296
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.13

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.4 This release

2 release files

0.1.3

2 release files

0.1.2

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page