AgentReadyHomeAgent ListingRuntimePricing

← Agent Listing

trailofbits-agentic-actions-auditor

Agent SkillsFreeOpen Source

Trail of Bits skill auditing GitHub Actions workflows for AI-agent integration security flaws.

🛡️ AgentReady threat assessment

MAESTRO 7-layer threat model + OWASP AIVSS risk score for trailofbits-agentic-actions-auditor, derived from its capabilities.

AIVSS 7.1 · High
View MAESTRO 7-layer threat model →

These scores are auto-generated from public information (the agent's own listing, docs, and repository) using the canonical OWASP AIVSS formula and the MAESTRO framework — an estimate for guidance, not a penetration test, audit, or certification. See the scoring methodology — every score is re-derived by the same automated method as an agent's public evidence changes.

Overview

Security skill that audits GitHub Actions workflows for vulnerabilities in AI-agent integrations (Claude Code Action, Gemini CLI, OpenAI Codex, GitHub AI Inference), detecting attack vectors where attackers can hijack agent runs. Analyzes workflow YAML as its file surface.

Key features and capabilities

Use cases