ci-workflow-doctor — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited ci-workflow-doctor (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Part of shipsafe — offline deploy-safety skills. Every script is stdlib-only Python 3.8+; nothing leaves the machine.
python3 scripts/lint_workflows.py <repo_root> [--json] # finds .github/workflows itselfChecks:
pull_request_target + checkout of the PR head runs untrusted fork code WITH repo secrets. This is the classic GitHub Actions exfiltration pattern; fix immediately.actions/* are exempt.${{ secrets.X }} interpolated into run: scripts leaks via shell tracing; pass via env: instead.Implementation note: parsing is line-structured and heuristic (zero dependencies, runs anywhere) — on exotic YAML, verify a finding against the file before asserting it.
Exit codes: 0 clean, 1 findings.
All paths below are relative to this skill's directory (ci-workflow-doctor/).
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.