GitHub Actions permission and dependency audit
Inspect one local workflow's declared token permission policies, exact needs edges, cycles and action references with complete JSON and CSV.
- 1Add input
- 2Adjust settings
- 3Get your result
Tool input and files are processed in this browser without being uploaded.
Before you start
Select a UTF8 YAML1.2 workflow snapshot. Resolve job permission mappings against the workflow declaration or explicit, unverified repository-default context. Keep omitted defaults unknown, preserve literal global modes and review exact declared dependencies and uses without executing expressions or contacting GitHub.
How to use this tool
- Choose one workflow YAML copied from your own repository.
- Leave unknown defaults selected unless you explicitly supply repository context; choose mapping only to parse the JSON box.
- Review permission origins, omitted-none scopes, missing or unresolved dependencies and exact cycle groups.
- Download full JSON and CSV with every original job declaration; review repository/runtime settings separately.
Supported inputs and limits
One file up to 5MiB; 100,000 resolved YAML value nodes, depth 64, 1,000 jobs, 10,000 declared needs and 10,000 uses. Default JSON up to 4KiB; complete JSON/CSV together 10MiB. All limits apply together. Preview only 200 jobs and 2,000 UTF16 characters per cell; downloads contain every record.
One YAML1.2 core document with unique string mapping keys, ordinary mappings/arrays/scalars and acyclic aliases only. yaml2.9.1 uses a weighted alias expansion guard of 50; this is not a promise to support 50 literal references. Custom/Set/binary/date tags, YAML1.1, cycles, duplicate keys, nonfinite or unsafe integer values and unsupported permission keys fail the whole review.
Permission keys are fixed to the 2026-10-07 profile. Job mappings replace workflow mappings; omitted scopes become none and {} is all-none. Missing defaults stay unknown. Supplied defaults remain unverified. read-all/write-all stay literal modes with no invented per-scope access.
This reads one provided snapshot, not a full workflow schema, security verdict or live token test. Fork/Dependabot/reusable-workflow/repository restrictions remain unknown. Matrix/conditions/needs expressions and job/step uses stay inert; no action fetching, repository edits, network requests or script execution. Cancellation discards all outputs.
Worked example
Example input
Six jobs: build/deploy/empty, cycleA/cycleB and after. Workflow contents: read/issues: write; deploy declares id-token: write; after needs an absent job and an expression.
Example options
{"repositoryDefault":"unknown","defaultPermissions":"{}"}Example output
Six complete records, seven declared needs, five existing edges, one two-job cycle, one missing target and one unresolved dependency; deploy contents is none, and downstream after is not part of the cycle.
When something does not work
Correct duplicate keys, unsupported types/permissions or the indicated limit, keep the original file and rerun. Split separately owned workflows and supply only context you know. Invalid input or cancellation yields no partial success files; retrying the same supported file rebuilds the complete report.
Frequently asked questions
Does job permissions merge with workflow permissions?
A job mapping replaces the workflow policy here. With workflow contents: read and job id-token: write, the job's contents becomes none. An explicit empty job mapping makes every supported scope none.
Can an unknown default or global mode prove runtime access?
No. Unknown stays unknown, supplied context is unverified, and read-all/write-all remains literal. Live token restrictions and referenced workflows cannot be inferred from one local file.
Documentation & further reading
Related tools
JSON formatting workspace
Format or minify strict JSON, sort object keys, and encode or decode strings while preserving raw number tokens.
Regex tester
Try a pattern and see what it matches in your text.
Compare text
See what changed, side by side.
HTML formatter
Format HTML indentation so its structure is easier to read.