{"uid":"cap_u8V3uX1ePwsSZsCcf_uUE","slug":"github-actions-workflow-security-scanner-51ff4c8c","name":"GitHub Actions Workflow Security Scanner","description":"Scan GitHub Actions workflow YAML for pull_request_target misuse, over-permissive tokens, secret leakage, unpinned actions, and unsafe fork checkout patterns.","url":"https://x402-hono-api.inraby.workers.dev/api/v1/github-actions-secret-exposure-scan","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"workflowYaml":{"type":"string","description":"GitHub Actions workflow YAML contents"}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.05","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.05/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.05","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.05","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_KmEDVoy3K-FISu_MejQXZ","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.05","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Scans GitHub Actions workflow YAML for security vulnerabilities including pull_request_target misuse, over-permissive tokens, secret leakage, unpinned actions, and unsafe fork checkout patterns","exampleAgentPrompt":"Can you scan this GitHub Actions workflow YAML for security issues — specifically check for pull_request_target misuse, over-permissive tokens, any secrets that might be leaking, unpinned actions, and unsafe fork checkout patterns?","exampleUseCases":null,"resultDescription":"A structured security report detailing vulnerabilities found in the workflow YAML, including identified instances of pull_request_target misuse, over-permissive GITHUB_TOKEN permissions, potential secret leakage paths, actions referenced without pinned SHA commits, and unsafe patterns for checking out code from forks.","failureModes":["Invalid or malformed YAML returns a parse error","Empty workflowYaml field returns a validation error","Non-GitHub-Actions YAML (e.g., Docker Compose) may return no findings or irrelevant results","Very large workflow files may time out","Payment failure (insufficient USDC balance) results in 402 response before scan executes"],"whenToPreferThis":"Use this endpoint when you need automated static analysis of GitHub Actions workflow files specifically for CI/CD security anti-patterns. It is purpose-built for GitHub Actions YAML rather than generic secret scanning or general-purpose SAST tools, making it ideal for DevSecOps pipelines, PR review automation, or security audits of open-source repositories where fork-based PR workflows are common.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T18:40:50.898Z","isFirstParty":false}