Audit GitHub Actions workflows for supply-chain and CI/CD security vulnerabilities — script injection, expression injection, token exfiltration, unpinned actions, cache poisoning, and Shai-Hulud-class self-replicating worms. Use when the user asks to audit, review, or check the security of GitHub Actions, workflows, CI/CD pipelines, or asks about supply-chain risk, npm publish security, or Shai-Hulud.
$npx -y skills add franky47/dotfiles --skill audit-github-actionsInstalls into the current project.
Run `npx skills use "https://github.com/franky47/dotfiles" --skill "franky47/dotfiles/audit-github-actions"` and follow the generated skill instructions now. Read its complete output, redirecting it to a temporary file first if necessary. Resolve relative paths from the supporting-files directory it provides.
Use the skills in "https://github.com/franky47/dotfiles" that are relevant to the current task. Run `npx skills add "https://github.com/franky47/dotfiles"` and select the relevant skills, then follow their instructions.