A fast scanning and attack toolkit for identifying and exploiting GitHub Actions vulnerabilities at scale.
Gato-X is an offensive security toolkit for GitHub Actions that identifies and exploits misconfigurations and vulnerabilities in CI/CD pipelines. It performs fast static analysis across thousands of repositories to detect issues like self-hosted runner takeovers, Pwn Requests, and secrets exposure that traditional scanners miss.
Red teamers, bug bounty hunters, and security engineers who need to identify and validate GitHub Actions vulnerabilities at scale.
Developers choose Gato-X for its speed, cross-repository analysis capabilities, and operator-focused design that prioritizes finding all potential vulnerabilities over minimizing false positives.
GitHub Attack Toolkit - Extreme Edition - A static analysis and exploit toolkit for GitHub Actions.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.
Capable of scanning 35-40 thousand repositories in 1-2 hours using a single GitHub PAT, enabling rapid large-scale security assessments.
Analyzes workflows and reusable actions across repositories to identify transitive vulnerabilities that single-repo scanners miss.
Identifies Pwn Requests, Actions Injection, TOCTOU vulnerabilities, and secrets exposure, focusing on real-world exploitable misconfigurations.
Tuned to avoid false negatives and provides all context needed to quickly verify true positives, saving time for security professionals.
Prioritizes comprehensive discovery over precision, resulting in more noise that requires manual investigation and verification.
Full attack functionality requires GitHub PATs with repo, workflow, and gist scopes, which can be a security concern and setup hurdle.
Exclusively targets GitHub Actions, missing vulnerabilities in other CI/CD systems or broader infrastructure security issues.