Agentic actions auditor
Audits CI workflows that invoke AI agents — where prompt injection becomes a repository write.
Installation
$ npx skills add trailofbits/skillsThe CLI's unit is the repository, so this installs everything in trailofbits/skills, not agentic-actions-auditor alone. It writes into whichever agent directories it finds — Claude Code, Codex, Cursor, Copilot, Windsurf, Zed.
Summary
Audits CI workflows that invoke AI agents — where prompt injection becomes a repository write.
- Reach for it when you just gave an agent a token in CI. This is the review of that decision.
- Sits in Secure — threat modelling, scanning, supply chain, and finding the other five copies of the bug you just found.
- Assumes ci/cd.
- Published by Trail of Bits. Well regarded, but not the vendor of the thing it covers.
- Installing pulls the whole trailofbits/skills repository: this catalogue lists 12 other entries from it, and the repo may hold more.
Where it sits in delivery
SecureThreat modelling, scanning, supply chain, and finding the other five copies of the bug you just found.Everything in Secure →
The agent itself
The full text lives with its publisher and changes when they change it. Read it there rather than here — a mirrored copy of somebody else's procedure goes stale silently, and this page would have no way of telling you.
Related
More in Secure
- Security threat modelProduces a threat model for a feature or system — assets, entry points, trust boundaries, mitigations.
openai/skills - Differential security reviewSecurity-focused review of a PR, commit or diff — risk-first, evidence-backed, with stated coverage limits.
trailofbits/skills - Fix reviewChecks that a fix actually closes the reported issue and did not just move it.
trailofbits/skills - Security best practicesOpenAI's secure-coding guidance for agent-written code.Skill
openai/skills - Supabase Postgres best practicesSchema, indexing and row-level security as Supabase recommends them.Skill
supabase/agent-skills - Supply chain risk auditorAudits dependencies and their provenance for supply-chain risk.
trailofbits/skills