managing-github-actions-secrets — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited managing-github-actions-secrets (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
PostHog centralizes all GitHub Actions secrets at the organization level and grants individual repositories access to them. Do not add secrets to a single repo, even if the secret is only consumed by one workflow today.
posthog org, not on a repo.(selected repositories). Do not make it available to all repos by default unless the secret is genuinely meant to be shared org-wide.
files. Pipe them in, or paste them only into the GitHub UI's secret field.
gh CLIPipe the secret value into gh secret set with --org posthog. The example below reads the value from stdin so it never appears in shell history:
# Read from clipboard / a pipe / a file — never inline as an argument
pbpaste | gh secret set POSTHOGOS_PACKAGER_KEY --org posthogCommon variants:
# From a file
gh secret set POSTHOGOS_PACKAGER_KEY --org posthog < secret.txt
# Restrict to selected repositories at creation time
gh secret set POSTHOGOS_PACKAGER_KEY --org posthog \
--visibility selected --repos PostHog/posthog,PostHog/posthog-foss
# Update which repos can access an existing org secret
gh secret set POSTHOGOS_PACKAGER_KEY --org posthog \
--visibility selected --repos PostHog/posthogVerify:
gh secret list --org posthog | grep POSTHOGOS_PACKAGER_KEYPOSTHOGOS_PACKAGER_KEY).exact repos that need it. Avoid All repositories unless the secret is safe to expose to every repo in the org.
gh secret set NAME without --org posthog — that creates arepo-level secret on whatever repo gh is currently pointed at.
Settings → Secrets and variables → Actions on anindividual repo to add a secret. If a repo-level secret already exists for something that should be org-level, migrate it (create at org, grant to the repo, then delete the repo-level copy).
accidentally exposed, rotate it immediately.
Default answer: at the org level via gh secret set --org posthog, granted to the specific repos that need it. Only deviate if the user explicitly overrides this (e.g. for an environment-scoped secret on a deployment environment, which is a different mechanism).
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.