/zizmor
Claude
zizmor
Audit GitHub Actions workflows, composite actions, Dependabot configs, and pre-commit configs for security findings using zizmor — template injection, credential persistence, unpinned uses, over-broad permissions, impostor commits. Covers local CLI, auto-fix, zizmor.yml policy, severity-based CI gates, SARIF upload, and pre-commit. Use when asked to "audit my workflows", "run zizmor", "is this workflow safe", "check for template injection", "pin my actions", or "set up a zizmor CI gate". Workflow syntax and shell errors → /platform-skills:github-actions (actionlint). IaC misconfig → /platform-skills:checkov. Image and dependency CVEs → /platform-skills:trivy. Keeping SHA pins fresh → /platform-skills:renovate.
More Claude commands
/effort
Set effort
Set the model effort/reasoning level.
/agents
Manage subagents
Create or manage subagents, or edit the agents directory directly.
/team-onboarding
Team onboarding
Generate a team onboarding guide from your usage history.
/deep-research
Deep research
Fan out web searches, cross-check sources, and synthesize a cited report.