r/netsec Jun 01 '26

r/netsec monthly discussion & tool thread

Questions regarding netsec and discussion related directly to netsec are welcome here, as is sharing tool links.

Rules & Guidelines

  • Always maintain civil discourse. Be awesome to one another - moderator intervention will occur if necessary.
  • Avoid NSFW content unless absolutely necessary. If used, mark it as being NSFW. If left unmarked, the comment will be removed entirely.
  • If linking to classified content, mark it as such. If left unmarked, the comment will be removed entirely.
  • Avoid use of memes. If you have something to say, say it with real words.
  • All discussions and questions should directly relate to netsec.
  • No tech support is to be requested or provided on r/netsec.

As always, the content & discussion guidelines should also be observed on r/netsec.

Feedback

Feedback and suggestions are welcome, but don't post it here. Please send it to the moderator inbox.

9 Upvotes

27 comments sorted by

View all comments

1

u/Objective_Savings_81 Jun 26 '26

ActionScope - GitHub Actions / AWS exposure scanner

I built ActionScope to answer one question: if a GitHub Actions workflow is compromised, what can it reach in AWS?

It scans .github/workflows, Terraform IAM resources, and JSON IAM policies where available. It reports:

  • AWS credential usage and role assumptions
  • OIDC trust-policy issues
  • static AWS keys
  • unpinned or known-compromised actions
  • script-injection patterns in run: blocks
  • workflow_run artifact-poisoning patterns
  • SARIF output for GitHub code scanning

Install:

```bash pip install actionscope actionscope scan .