WorkflowPromptGuard v0.1.0
WorkflowPromptGuard 0.1.0
Initial public release of the offline policy-as-code scanner for AI-enabled GitHub workflows.
- Traces untrusted GitHub content into write-capable AI agents, secrets, tools, and executable sinks.
- Covers GitHub Agentic Workflows plus Claude, Codex, Copilot, and Gemini action patterns.
- Ships 12 explainable rules, console/JSON/Markdown/SARIF output, a composite GitHub Action, and reasoned/expiring suppressions.
- Includes 37 tests, Python 3.10-3.14 CI, typed APIs, and vulnerable/safe examples.