repo-security-posture - Audit GitHub Repository Security Posture and Hardening Gaps
Audit a GitHub repository configuration and CI/CD workflows to identify security gaps and generate prioritized hardening tasks.
Tags
Updated: 2026-09-18Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Collect repository inventory and configuration
- Audit branch and merge protection
- Audit CODEOWNERS and collaborator access
- Audit GitHub Actions CI/CD workflows
- Review release and dependency security
- Generate prioritized security hardening report
Inputs
- GitHub repository identifier (owner/name)
- GitHub access token
- Repository configuration files and workflows
Outputs
- Markdown security hardening report
- Structured audit inventory JSON file
- JSON formatted security findings list
Requirements
- Python 3 runtime environment
- Network access to api.github.com
- Network access to raw.githubusercontent.com
