bitwarden/action-remediate
> Remediate GitHub Actions action findings identified by the action-audit skill. Applies the appropriate fix per action type — `@main` ref for internal `bitwarden/` actions, full SHA with inline version comment for external actions, or full replacement — across selected repos and creates draft PRs. Run the action-audit skill first to identify findings before using this skill. <example> </example> <example> </example>
npx skills add https://github.com/bitwarden/ai-plugins --skill action-remediate
gh api GET requests are allowed freely. Any call using -X POST, -X PUT, -X PATCH, or -X DELETE must be shown to the user and approved before execution..github/. Do not touch application code, scripts, or configuration outside of workflow files.Before proceeding, verify that the user has audit findings to act on. These should come from a prior run of the action-audit skill. Confirm:
bitwarden/ actions: change the ref to @main@main is the fixIf any of this is unclear, ask the user before continuing.
For each selected repo:
<base-dir>/<repo>. If not, inform the user and skip that repo. git checkout -b fix/action-remediation-<action-name-slug>
bitwarden/ actions): Replace the ref with @main — e.g., uses: bitwarden/gh-actions/action@v1 → uses: bitwarden/gh-actions/action@main. No SHA resolution needed.uses: line with uses: <action>@<sha> # <original-ref>bitwarden/workflow-linter. Then swap uses: <old-action>@<ref> with uses: <new-action>@<sha> # <tag>git diff of changes in this repo and get confirmation before proceeding.Do not run the staging, commit, or push commands yourself. For each repo, present the block below for the user to run manually as a suggestion:
git add .github/
git commit -m "Remediate <action-name> action usage"
git push -u origin fix/action-remediation-<action-name-slug>
Once the user confirms the push, create the draft PR:
gh pr create \
--title "Remediate <action-name> action usage" \
--body "$(cat <<'EOF'
## Summary
Remediates usage of `<action-name>` across this repository.
**Action taken:** <pin updated to `<sha>` / replaced with `<new-action>`>
**Reason:** <compromised action / deprecated action / unpinned reference>
EOF
)" \
--draft
Output a summary of all actions taken:
| Repo | Files Changed | PR Created | Notes |
| ---- | ------------- | ---------- | ----- |
| ... | ... | ... | ... |
Remind the user that code search results may have a lag and to verify no repos were missed by checking manually if this is a security incident.
Take bitwarden/action-remediate from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.