Skip to content

Consent request: lightweight AI workflow safety review #525

Description

@sho-tado

Hi maintainers,\n\nI maintain �gentic-actions-guard, a small OSS scanner for AI/agent GitHub Actions workflow boundaries: https://github.com/sho-tado/agentic-actions-guard\n\nI'm doing consent-first reviews of public AI GitHub Actions workflows. The review looks only at public workflow files and focuses on maintainer-safety boundaries such as untrusted GitHub event input, secrets, token permissions, pull_request_target, checkout credentials, mutable AI action refs, and AI output flowing into shell execution.\n\nWould you be open to receiving a lightweight Markdown review report for this repository's public workflows?\n\nIf yes, I'll share a concise report in this issue or wherever you prefer. If not, no worries, I will not post repo-specific findings.\n\nI will not include secrets, private prompts, exploit payloads, or non-public repository content.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions