Skip to content
#

script-injection

Here are 3 public repositories matching this topic...

taint-trail

Follows an untrusted GitHub Actions value after it leaves run:, through env:, with:, step outputs and into the called action, until it dies in argv, reaches a shell, spoofs GITHUB_OUTPUT, or becomes opaque with the reason named. An injection that moved is not an injection that was fixed.

  • Updated Sep 23, 2026
  • Python

Add this topic to your repo

To associate your repository with the script-injection topic, visit your repo's landing page and select "manage topics."

Learn more