Review agent · Infra & pipeline

CI/CD pipeline

Checks pipelines for leaked secrets, untrusted code execution and over-broad tokens.

.github/workflows/pr.yml1on: pull_request_target2steps:3 - uses: actions/checkout@v44 - uses: some/action@mainCI/CDwhat this review answersFork code running with secrets?Actions pinned by commit SHA?Job token permissions scoped?$ verdict REAL ISSUE$ fix pin by SHA, scope the token▍

Illustrative example of how this agent reviews a finding.

Why this agent matters

Your pipeline holds deploy keys and publishes artifacts, which makes it a prime target. The 2021 Codecov incident showed how a tampered CI script could exfiltrate secrets from thousands of pipelines.

Workflow YAML is rarely reviewed with the same care as code. This agent looks at the build-time trust decisions: what runs, with which secrets and which permissions.

What it checks

  • Secrets printed or exposed in build logs
  • pull_request_target workflows that check out fork code
  • Third-party actions or images not pinned by SHA
  • Excessive job token permissions

When it marks a finding as a likely false positive

  • Untrusted code never runs with secrets
  • Actions are pinned and tokens scoped

The fix it suggests

  • Scoping job token permissions
  • Pinning actions by commit SHA
  • Masking secrets and isolating fork builds

Scope and limits

This agent validates findings reported by Semgrep, Gitleaks and Trivy; it doesn't hunt for new bugs on its own. A finding reaches it when its CWE or rule/path keywords match this vulnerability class. It sees only the minimal code around the finding, with secrets redacted, and returns a verdict with a confidence score, a plain-English explanation and a suggested patch.

Common questions

Why pin actions by SHA instead of a tag?

Tags can be moved to point at different code. A commit SHA can't, so a compromised upstream can't silently change what your pipeline runs.

Related agents

  • Infrastructure & IaC — Reviews Terraform, Helm, Ansible and server config for insecure defaults and exposure.
  • Cloud security — Checks cloud resources for public exposure, wildcard IAM and long-lived keys.
  • Container & Kubernetes — Checks Dockerfiles and Kubernetes manifests for root, privileged and host-level access.

See all 20 review agents → · Agent setup reviewer · How the pipeline works

Run the CI/CD pipeline agent on your repository

100 free credits, no credit card. Every finding comes with a verdict and a fix.

Get started free