LogoClawIndex
CasesSkillsAbout
LogoClawIndex

ClawIndex

OpenClaw Skills & Use Case Index

ClawIndex is an ecosystem-driven index of OpenClaw skills and real-world use cases.

Index

Skills·
Cases

Meta

About·
Disclaimer·
Email·
GitHub
© 2026 ClawIndex All Rights Reserved.

hunt-cicd - Hunt CI/CD Pipeline Vulnerabilities

Identifies and validates vulnerabilities in GitHub Actions, Jenkins, GitLab CI, runners, OIDC policies, Terraform state, logs, and artifacts.

Tags

Updated: 2026-10-03

Capabilities

Typical Inputs

Typical Outputs

What this skill does

  • Fingerprint Jenkins instances
  • Validate script console access
  • Test Jenkins file read
  • Inspect workflow injection sinks
  • Analyze runner poisoning risks
  • Inspect OIDC trust policies
  • Parse Terraform state exposure
  • Check logs and artifacts
  • Confirm findings with proof

Inputs

  • Target CI/CD URLs
  • GitHub organization data
  • Workflow files
  • Jenkins responses
  • IAM trust policies
  • Terraform state files
  • CI logs and artifacts
  • Out-of-band callback endpoint

Outputs

  • Validated vulnerability findings
  • Proof-of-exploitation responses
  • Leaked file contents
  • Exposed secrets
  • Cloud identity responses
  • Security assessment results

Requirements

  • Network access to target services
  • curl command
  • GitHub CLI access
  • jq command
  • AWS CLI access
  • Java runtime
  • Out-of-band callback service

Source

  • Spec: SKILL.md
CI/CD security
GitHub Actions
Jenkins
GitLab CI
Runner security
OIDC
Terraform
Secret leakage
Pipeline injection
Fingerprint Jenkins instances
Validate script console access
Test Jenkins file read
Inspect workflow injection sinks
Target CI/CD URLs
GitHub organization data
Workflow files
Validated vulnerability findings
Proof-of-exploitation responses
Leaked file contents