Skip to content

Repo Agent Instruction Security Scan v1.2.0

Latest

Choose a tag to compare

@github-actions github-actions released this 02 Sep 07:19

What changed

  • Scans every SKILL.md in addition to AGENTS.md, CLAUDE.md, Gemini, Cursor, Copilot, Claude, and Windsurf instruction files.
  • Applies the existing eight deterministic review signals to Agent Skills without executing their instructions or bundled code.
  • Preserves the 150 KB per-file limit, 200-file cap, dependency-directory exclusions, symlink exclusion, and workspace path boundary.
  • Updates the GitHub Action, pre-commit hook, CLI documentation, and regression suite for the expanded instruction surface.

Verification

  • All seven deterministic tests pass.
  • The public release workflow smoke-tested the packaged CLI and pre-commit integration.
  • A fresh public-asset install detected a high-severity download-and-execute chain inside skills/review/SKILL.md.
  • The release archive carries signed GitHub build provenance.

Verify the downloaded archive before execution:

gh attestation verify repo-agent-instruction-security-scan-1.2.0.tar.gz -R sunxiayi/repo-agent-instruction-security-scan

SHA-256: d47c96668525357f60d0b9528118bc668f8eaabf7e2fd0fe87809536115851da