---
name: "Audit GitHub Actions for privilege and supply-chain risks with zizmor"
slug: "audit-github-actions-for-privilege-and-supply-chain-risks-with-zizmor"
description: "Run a focused security pass on GitHub Actions workflows before merge so token misuse, dangerous permissions, and unpinned actions are caught early."
github_stars: 4186
verification: "listed"
source: "https://github.com/zizmorcore/zizmor"
author: "zizmorcore"
publisher_type: "organization"
category: "Security & Verification"
framework: "Multi-Framework"
tool_ecosystem:
  github_repo: "zizmorcore/zizmor"
  github_stars: 4186
---

# Audit GitHub Actions for privilege and supply-chain risks with zizmor

Run a focused security pass on GitHub Actions workflows before merge so token misuse, dangerous permissions, and unpinned actions are caught early.

## Prerequisites

Python 3.9+ or prebuilt zizmor binary, access to the target repository

## Installation

Basic usage or getting-started notes:
- [detailed usage recipes].
- [detailed usage recipes]: https://docs.zizmor.sh/usage/

- Source: https://github.com/zizmorcore/zizmor
- Extracted from upstream docs: https://raw.githubusercontent.com/zizmorcore/zizmor/HEAD/README.md

## Documentation

- https://woodruffw.github.io/zizmor/

## Source

- [Agent Skill Exchange](https://agentskillexchange.com/skills/audit-github-actions-for-privilege-and-supply-chain-risks-with-zizmor/)
