OpenSSF Scorecard
Critical-risk checks – OpenSSF Scorecard

OpenSSF Scorecard Dangerous-Workflow: Dangerous-Workflow check

Scorecard inspects the project's GitHub Actions workflows for two dangerous patterns: an untrusted code checkout, where a pull_request_target or workflow_run trigger (which runs with write permission and access to the target repository's secrets) is combined with an explicit checkout of the pull request's code; and script injection, where an inline script interpolates attacker-controllable context values such as an issue title so that they may execute on the runner. Full marks require every workflow to avoid both patterns. The check does not recognise safe uses, such as a checkout gated on a maintainer label.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-218 · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Critical-risk checks – OpenSSF Scorecard

Query this from an agent

The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.