소개
This skill provides a structured framework for assessing the security of third-party GitHub Actions before they are integrated into your workflows. It guides developers through identifying trust tiers, performing source code reviews, and implementing critical mitigation strategies like immutable SHA pinning, job-level permission scoping, and forking sensitive dependencies. By automating the risk evaluation process, it helps teams protect repository secrets and cloud credentials from potentially malicious or compromised community actions, ensuring a secure and resilient deployment environment.