I will audit your github actions workflows for cache poisoned secret leaks

United States

I speak English

AI Automation and Agent Builder

I build AI agents and automations that run unattended. I run 60+ scheduled jobs across my own businesses — email triage, outreach, listings, reporting — so every service I sell is something I use dail...
About this Gig

Your CI caches speed up builds. They can also carry your credentials to anyone who opens a pull request.


If a workflow runs cargo login, docker login or npm login, or writes a secret into a folder that actions/cache saves, the next job that restores that cache gets the token, including jobs triggered by outside pull requests. It is easy to miss in review because the two halves sit in different steps or different files.


What you get:

Every workflow in your repo checked for credential files inside cached paths, secrets written into cached folders, pull-request jobs that restore a cache a privileged job tainted, and checkout tokens left in .git/config.

A findings table with the exact workflow.yml:line for each problem and why it matters.

A copy-paste fix diff for each finding.

One re-check after you apply the fixes.


What I need: read access to the repo, or a zip of .github/workflows. Nothing is run against your infrastructure.


Reusable workflows and composite actions are reviewed by hand; the report says which ones I read.

Tools:

GitHub

Frameworks:

Npm

Cloud Provider:

Other

Programming language:

Bash

•

Python

Expertise:

Debugging

•

Configuration

My Portfolio