Open-source Workflow Security Auditor
actsense
See every dependency your CI workflows actually run, at the exact version they run, and what each one exposes. Then fix it.
Works with GitHub Actionsdocker run --rm -p 8000:8000 ghcr.io/0xcardinal/actsense:latest
- Comprehensivedocumented checks, each with a fix
- Every layercomposite actions, reusable workflows, images
- Pinned refsaudited at the version that runs, not
main - 1 containerself-hosted; your workflows stay with you
The attacks it catches
The patterns behind real CI/CD compromises, found in your workflows and in every dependency they pull in. Shown here for GitHub Actions.
Pwn requests
pull_request_target workflows that check out and run a fork's code with your secrets and a write token.
Script injection
PR titles, branch names and comments interpolated straight into run:, where they execute as shell.
Environment poisoning
Untrusted text written to $GITHUB_ENV or $GITHUB_PATH, hijacking every later step.
Runner takeover
Self-hosted runners that pull requests from forks can reach, in a public repository.
CriticalLeaked credentials
Hardcoded keys and tokens, verified with TruffleHog, plus static cloud keys where OIDC should be.
Supply chainMutable dependencies
Actions pinned to movable tags, unpinned images and packages, typosquats and archived actions.
How it works
- 1
Point it at a repository
An
owner/repo, a singleowner/repo@refaction, or a workflow file you paste in. - 2
It maps the whole supply chain
Workflows, local and remote actions, nested reusable workflows, Docker base images and installed packages, each fetched at the ref your workflow pins.
- 3
Every node is audited
Findings land on the exact node and line, ranked by severity, each linked to a page explaining the risk and the fix.
Fix, not just flag
The workflow editor turns findings into line-level fixes you can apply in one click. Tags are resolved to commit SHAs and image digests through pin., so pinning works without a GitHub token.
- - uses: actions/checkout@v4
+ - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
- container: nginx:1.27
+ container: nginx@sha256:6784fb08…c05f7d # 1.27Supported platforms
actsense is a workflow security auditor. GitHub Actions is fully supported today; the engine is built so other workflow platforms can be added.
Available now
GitHub Actions
Workflows, composite and JavaScript actions, reusable workflows, Docker actions and job containers.
Get started →Planned — tell us which one you need