$npx skillfedfor your agent

zizmor

Static analysis for GitHub Actions

Worth itPyPI SecurityReleased Aug 20265.0M downloads / moMITPlatform wheel

Decision gist · record as of 2026-08-14

platform wheels — zizmor-1.29.0-py3-none-macosx_10_12_x86_64.whl · zizmor-1.29.0-py3-none-macosx_11_0_arm64.whl · zizmor-1.29.0-py3-none-manylinux_2_24_aarch64.whl
v1.29.0 · released 2026-08-01 · Python >=3.10

Yes. zizmor addresses a genuine gap in CI/CD security tooling with active maintenance, zero runtime dependencies, permissive licensing, and broad platform support. It is worth installing if you use GitHub Actions, Dependabot, or pre-commit and want to catch configuration-level security issues before they reach production.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.10 or later.
  • Medium install friction due to platform-specific wheels across multiple architectures (macOS, Linux, Windows, ARM variants).
  • Active maintenance with a recent release and no runtime dependencies simplifies deployment once installed.

License · maintenance · safety

MIT (permissive) — MIT license permits unrestricted use, modification, and distribution with minimal obligations—suitable for both commercial and open-source projects.

last release 2026-08-01 (13 days) · last repo commit 2026-08-13 · 6,028 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 5,027,136 downloads/mo, #2,179 on PyPI

Verify before relying

pip install zizmor
zizmor lint .github/workflows/
  • Specific categories of security issues detected beyond those listed (template injection, credential leakage, permission scopes, impostor commits).
  • Whether zizmor can automatically fix identified issues or only report them.
  • Performance characteristics on large workflow repositories or complex configurations.
Same gist for agents: .md · .json

What it is and what it does

zizmor is a static analysis tool designed to audit CI/CD pipelines for security misconfigurations. It examines GitHub Actions workflows, Dependabot configurations, and pre-commit hooks to detect vulnerabilities including template injection that could lead to code execution, accidental credential persistence, overly broad permission grants, and git reference spoofing. The tool runs locally as a command-line utility with no external dependencies, making it straightforward to integrate into development workflows or CI systems themselves.

The package is actively maintained, recently released, and backed by established security organizations. It targets modern Python (3.10+) and ships as pre-built wheels for common platforms, eliminating compilation friction. With no runtime dependencies and permissive MIT licensing, it presents minimal adoption barriers for teams seeking to harden their CI/CD security posture.

Use it for

  • Audit GitHub Actions workflows before merging to catch template injection and credential exposure risks.
  • Scan Dependabot configurations to ensure dependency updates don't grant excessive permissions.
  • Validate pre-commit hook setups to prevent compromised hooks from executing arbitrary code.
  • Integrate into CI pipelines to enforce security checks on workflow file changes.
  • Review existing workflow repositories for historical misconfigurations and permission creep.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

zizmor addresses a genuine gap in CI/CD security tooling with active maintenance, zero runtime dependencies, permissive licensing, and broad platform support. It is worth installing if you use GitHub Actions, Dependabot, or pre-commit and want to catch configuration-level security issues before they reach production.

Install

zizmor on PyPI

Before you install

Medium install friction due to platform-specific wheels across multiple architectures (macOS, Linux, Windows, ARM variants). Active maintenance with a recent release and no runtime dependencies simplifies deployment once installed.

Requires Python 3.10 or later.

License in practice

MIT license permits unrestricted use, modification, and distribution with minimal obligations—suitable for both commercial and open-source projects.

Quickstart

pip install zizmor
zizmor lint .github/workflows/

Verify before relying

  • Specific categories of security issues detected beyond those listed (template injection, credential leakage, permission scopes, impostor commits).
  • Whether zizmor can automatically fix identified issues or only report them.
  • Performance characteristics on large workflow repositories or complex configurations.

Package facts

LicenseMIT permissive
Python supportSupports the current Python release >=3.10
Install frictionMedium. Platform-specific wheel
Runtime dependenciesNone
MaintenanceActively maintained 13 days since the last release
Last repo commit
First released
Downloads5,027,136 / month, #2,179 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14

Evidence: zizmor-1.29.0-py3-none-macosx_10_12_x86_64.whl; zizmor-1.29.0-py3-none-macosx_11_0_arm64.whl; zizmor-1.29.0-py3-none-manylinux_2_24_aarch64.whl; zizmor-1.29.0-py3-none-manylinux_2_28_armv7l.whl; zizmor-1.29.0-py3-none-manylinux_2_28_x86_64.whl; zizmor-1.29.0-py3-none-musllinux_1_2_aarch64.whl; zizmor-1.29.0-py3-none-musllinux_1_2_armv7l.whl; zizmor-1.29.0-py3-none-musllinux_1_2_x86_64.whl; zizmor-1.29.0-py3-none-win32.whl; zizmor-1.29.0-py3-none-win_amd64.whl

Tags

Capabilities
github actions security scannerci/cd static analysis toolworkflow vulnerability detectiongithub actions linterci/cd security auditdependabot security checkworkflow configuration analysis
Topics
ci-cd-securitystatic-analysisgithub-actions

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “github actions security scanner”

  • zizmorzizmor is a static analysis tool that scans CI/CD…
  • cisco-ai-skill-scannerScans AI Agent Skills for prompt injection, data exfiltration, and…
  • guarddogGuardDog is a CLI tool that scans PyPI, npm, Go, Rust, RubyGems,…

Give your agent the search over MCP, or paste the wish link into any chat.

More Security packages

SecretStorage With conditions
PyPI · Python Modules · released Nov 2025

Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.

BSD-3-Clausepure Python · 3.10+aging
226.9Mdownloads / mo
msal Worth it
PyPI · Security · released May 2026

MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.

MITpure Python · 3.9+
223.0Mdownloads / mo
joserfc Worth it
PyPI · Security · released Jul 2026

joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.

BSD-3-Clausepure Python · 3.10+
155.5Mdownloads / mo
Authlib Worth it
PyPI · Security · released May 2026

Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.

BSD-3-Clausepure Python · 3.10+
155.1Mdownloads / mo
argon2-cffi-bindings With conditions
PyPI · Python Modules · released Jul 2025

Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.

MITcompiled wheel · 3.9+
74.2Mdownloads / mo
adal Skip
PyPI · Security · released Apr 2021

ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.

Install only if maintaining existing code that already depends on it, and plan a migration.

MITpure Pythonabandoned
44.5Mdownloads / mo

See also flawfinder · gitlint · dodgy · csaf-tool · llm-guard · libsast · pip-audit · pyre-check · ick · deepteam