githubnext / githubnext/awesome-continuous-ai
[SUBMISSION] Agentic Workflow Guard
- Dominant language
- No language data
- Stars
- 491
- Forks
- 32
- PR merge metrics
- No merged PRs in 30d
Description
### Title
Agentic Workflow Guard
### Description
A deterministic, model-free GitHub Action and CLI that statically analyzes AI-agent GitHub Actions workflows for Agentic Workflow Injection paths.
It detects workflow-level risk patterns such as untrusted issue, pull request, comment, commit, or dispatch text reaching AI prompt inputs; AI jobs with risky token permissions or exposed secrets; and agent-derived output flowing into scripts, release commands, package publishing, cloud CLIs, or other sensitive sinks.
It produces Markdown, JSON, and SARIF output and is designed to complement general GitHub Actions security scanners. Suggested placement: **Continuous Security**.
Disclosure: I am submitting a project maintained by `jinyounghub`.
### URL
https://github.com/jinyounghub/agentic-workflow-guard
### Category
Other (please specify in description)
### Submission Guidelines
- [x] The resource is related to AI-powered automation for software collaboration
- [x] The resource is publicly accessible
- [x] I have checked that this resource is not already listed in the repository
Contributor guide
Research direction
Start by reviewing the awesome-continuous-ai repository's list structure and the submitted project at https://github.com/jinyounghub/agentic-workflow-guard. Follow the repository's existing submission format and place Agentic Workflow Guard under Continuous Security. Done means the resource is listed with its URL and the submission does not duplicate an existing entry.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github-actions
- Domain
- content, documentation
- Issue type
- Documentation
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 68/100