CI and build security / FREE TOOL
GitHub Actions review
Review workflow permissions, action pinning, privileged triggers, and untrusted expressions before they reach your build.
02 Your results
A closer look starts here.
Add your input and run the check. We will show the observations and explain what needs review.
A QUICK WALKTHROUGH
How to use it
- 01Paste one workflow YAML file or load the synthetic example.
- 02Review permissions, action references and input handling.
- 03Confirm each signal in the repository and runner context before changing the workflow.
What this check can tell you
Local YAML review, not execution or a complete GitHub Actions validator. Repository settings, referenced workflows, action contents and current runner protections are not inspected. Aliases, merge keys and custom YAML tags are unsupported. Maximum workflow size: 200,000 characters.
The initial review processes files in this tab. If you choose the optional AI summary, the displayed findings are sent to Cloudflare AI; your raw file, result tables and decoded token claims are excluded.
GitHub Actions secure use reference