I will audit your github actions workflows for cache poisoned secret leaks
AI Automation and Agent Builder
About this Gig
Your CI caches speed up builds. They can also carry your credentials to anyone who opens a pull request.
If a workflow runs cargo login, docker login or npm login, or writes a secret into a folder that actions/cache saves, the next job that restores that cache gets the token, including jobs triggered by outside pull requests. It is easy to miss in review because the two halves sit in different steps or different files.
What you get:
Every workflow in your repo checked for credential files inside cached paths, secrets written into cached folders, pull-request jobs that restore a cache a privileged job tainted, and checkout tokens left in .git/config.
A findings table with the exact workflow.yml:line for each problem and why it matters.
A copy-paste fix diff for each finding.
One re-check after you apply the fixes.
What I need: read access to the repo, or a zip of .github/workflows. Nothing is run against your infrastructure.
Reusable workflows and composite actions are reviewed by hand; the report says which ones I read.
Tools:
GitHub
Frameworks:
Npm
Cloud Provider:
Other
Programming language:
Bash
•
Python
Expertise:
Debugging
•
Configuration
