Skip to main content
CI and build security tools

CI and build security / FREE TOOL

GitHub Actions review

Review workflow permissions, action pinning, privileged triggers, and untrusted expressions before they reach your build.

Local review / optional AI

01 Your input

Local processing only. Maximum file size: 2 MB.

02 Your results

A closer look starts here.

Add your input and run the check. We will show the observations and explain what needs review.

 

A QUICK WALKTHROUGH

How to use it

  1. 01Paste one workflow YAML file or load the synthetic example.
  2. 02Review permissions, action references and input handling.
  3. 03Confirm each signal in the repository and runner context before changing the workflow.

What this check can tell you

Local YAML review, not execution or a complete GitHub Actions validator. Repository settings, referenced workflows, action contents and current runner protections are not inspected. Aliases, merge keys and custom YAML tags are unsupported. Maximum workflow size: 200,000 characters.

The initial review processes files in this tab. If you choose the optional AI summary, the displayed findings are sent to Cloudflare AI; your raw file, result tables and decoded token claims are excluded.

GitHub Actions secure use reference