Skip to content

[SUBMISSION] Agentic Workflow Guard #78

Description

@jinyounghub

Title

Agentic Workflow Guard

Description

A deterministic, model-free GitHub Action and CLI that statically analyzes AI-agent GitHub Actions workflows for Agentic Workflow Injection paths.

It detects workflow-level risk patterns such as untrusted issue, pull request, comment, commit, or dispatch text reaching AI prompt inputs; AI jobs with risky token permissions or exposed secrets; and agent-derived output flowing into scripts, release commands, package publishing, cloud CLIs, or other sensitive sinks.

It produces Markdown, JSON, and SARIF output and is designed to complement general GitHub Actions security scanners. Suggested placement: Continuous Security.

Disclosure: I am submitting a project maintained by jinyounghub.

URL

https://github.com/jinyounghub/agentic-workflow-guard

Category

Other (please specify in description)

Submission Guidelines

  • The resource is related to AI-powered automation for software collaboration
  • The resource is publicly accessible
  • I have checked that this resource is not already listed in the repository

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requesthelp wantedExtra attention is needed

    Type

    No type

    Fields

    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions