hunt-cicd - Detect CI/CD pipeline security vulnerabilities
Detect and validate CI/CD security flaws across GitHub Actions, Jenkins, runners, OIDC policies, Terraform state, logs, artifacts, and pipeline secrets.
Tags
Updated: 2026-10-03Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Detect Jenkins console exposure
- Validate Jenkins file-read flaws
- Analyze GitHub Actions injection
- Assess runner poisoning
- Inspect OIDC trust policies
- Identify Terraform state leakage
- Check secret leakage
Inputs
- CI/CD target endpoints
- GitHub or GitLab organization
- Workflow and pipeline configurations
- Jenkins version information
- IAM trust policies
- Accessible logs and artifacts
- OOB callback endpoint
Outputs
- Validated vulnerability findings
- Reproducible proof-of-impact evidence
- Secret or file exposure evidence
- Out-of-band callback evidence
Requirements
- Network access to targets
- Shell command-line environment
- curl, jq, and gh CLI
- AWS CLI for IAM checks
- Java for Jenkins CLI checks
- Burp Collaborator or interactsh for blind injection
