Title
Agentic Workflow Guard
Description
A deterministic, model-free GitHub Action and CLI that statically analyzes AI-agent GitHub Actions workflows for Agentic Workflow Injection paths.
It detects workflow-level risk patterns such as untrusted issue, pull request, comment, commit, or dispatch text reaching AI prompt inputs; AI jobs with risky token permissions or exposed secrets; and agent-derived output flowing into scripts, release commands, package publishing, cloud CLIs, or other sensitive sinks.
It produces Markdown, JSON, and SARIF output and is designed to complement general GitHub Actions security scanners. Suggested placement: Continuous Security.
Disclosure: I am submitting a project maintained by jinyounghub.
URL
https://github.com/jinyounghub/agentic-workflow-guard
Category
Other (please specify in description)
Submission Guidelines
Title
Agentic Workflow Guard
Description
A deterministic, model-free GitHub Action and CLI that statically analyzes AI-agent GitHub Actions workflows for Agentic Workflow Injection paths.
It detects workflow-level risk patterns such as untrusted issue, pull request, comment, commit, or dispatch text reaching AI prompt inputs; AI jobs with risky token permissions or exposed secrets; and agent-derived output flowing into scripts, release commands, package publishing, cloud CLIs, or other sensitive sinks.
It produces Markdown, JSON, and SARIF output and is designed to complement general GitHub Actions security scanners. Suggested placement: Continuous Security.
Disclosure: I am submitting a project maintained by
jinyounghub.URL
https://github.com/jinyounghub/agentic-workflow-guard
Category
Other (please specify in description)
Submission Guidelines