Neatbo.

GitHub Actions permission and dependency audit

Inspect one local workflow's declared token permission policies, exact needs edges, cycles and action references with complete JSON and CSV.

Browser-local processingInputOne local UTF8 YAML1.2 workflowOutputComplete permission/dependency JSON and CSVUp to 5 MiB per file · File limit: 1
  1. 1Add input
  2. 2Adjust settings
  3. 3Get your result

Tool input and files are processed in this browser without being uploaded.

Your input

Inputs are kept temporarily in this tab when switching tools. Refreshing or closing clears them; large results may need to be regenerated.

⌘ / Ctrl + Enter to run

or drag and drop it here

Files stay on this device. Your originals stay unchanged.

.yml · .yaml

Up to 5 MiB per file · File limit: 1

    Options

    Complete the required options first. You can keep the defaults for the rest.

    Explicit user context only; no repository lookup or live verification.

    Parsed only when JSON mapping is selected; the 4KiB text budget always applies. Mapping omissions become none.

    Preparing the tool…

    Before you start

    Select a UTF8 YAML1.2 workflow snapshot. Resolve job permission mappings against the workflow declaration or explicit, unverified repository-default context. Keep omitted defaults unknown, preserve literal global modes and review exact declared dependencies and uses without executing expressions or contacting GitHub.

    How to use this tool

    1. Choose one workflow YAML copied from your own repository.
    2. Leave unknown defaults selected unless you explicitly supply repository context; choose mapping only to parse the JSON box.
    3. Review permission origins, omitted-none scopes, missing or unresolved dependencies and exact cycle groups.
    4. Download full JSON and CSV with every original job declaration; review repository/runtime settings separately.

    Supported inputs and limits

    One file up to 5MiB; 100,000 resolved YAML value nodes, depth 64, 1,000 jobs, 10,000 declared needs and 10,000 uses. Default JSON up to 4KiB; complete JSON/CSV together 10MiB. All limits apply together. Preview only 200 jobs and 2,000 UTF16 characters per cell; downloads contain every record.

    One YAML1.2 core document with unique string mapping keys, ordinary mappings/arrays/scalars and acyclic aliases only. yaml2.9.1 uses a weighted alias expansion guard of 50; this is not a promise to support 50 literal references. Custom/Set/binary/date tags, YAML1.1, cycles, duplicate keys, nonfinite or unsafe integer values and unsupported permission keys fail the whole review.

    Permission keys are fixed to the 2026-10-07 profile. Job mappings replace workflow mappings; omitted scopes become none and {} is all-none. Missing defaults stay unknown. Supplied defaults remain unverified. read-all/write-all stay literal modes with no invented per-scope access.

    This reads one provided snapshot, not a full workflow schema, security verdict or live token test. Fork/Dependabot/reusable-workflow/repository restrictions remain unknown. Matrix/conditions/needs expressions and job/step uses stay inert; no action fetching, repository edits, network requests or script execution. Cancellation discards all outputs.

    Worked example

    Example input

    Six jobs: build/deploy/empty, cycleA/cycleB and after. Workflow contents: read/issues: write; deploy declares id-token: write; after needs an absent job and an expression.
    Example options
    {"repositoryDefault":"unknown","defaultPermissions":"{}"}

    Example output

    Six complete records, seven declared needs, five existing edges, one two-job cycle, one missing target and one unresolved dependency; deploy contents is none, and downstream after is not part of the cycle.

    When something does not work

    Correct duplicate keys, unsupported types/permissions or the indicated limit, keep the original file and rerun. Split separately owned workflows and supply only context you know. Invalid input or cancellation yields no partial success files; retrying the same supported file rebuilds the complete report.

    Frequently asked questions

    Does job permissions merge with workflow permissions?

    A job mapping replaces the workflow policy here. With workflow contents: read and job id-token: write, the job's contents becomes none. An explicit empty job mapping makes every supported scope none.

    Can an unknown default or global mode prove runtime access?

    No. Unknown stays unknown, supplied context is unverified, and read-all/write-all remains literal. Live token restrictions and referenced workflows cannot be inferred from one local file.

    Documentation & further reading

    Related tools