Skip to content

[static-analysis] RGS-012: Secret Exfiltration via Outbound HTTP Request in visual-regression-checker.lock.ymlΒ #51945

Description

@github-actions

🚨 Runner-Guard Security Finding

Rule: RGS-012 β€” Secret Exfiltration via Outbound HTTP Request
Severity: High
File: .github/workflows/visual-regression-checker.lock.yml
Line: 527 (also recurs at line 894 β€” 2 occurrences in this file)

Description

A run: block contains an outbound HTTP request command (curl, wget, httpie, python requests, node fetch, etc.) targeting a non-GitHub domain (i.e., not github.com, api.github.com, or ghcr.io) in a job context that has access to secrets or publishing capabilities. This pattern is a strong indicator of credential exfiltration β€” the primary objective of most GitHub Actions supply-chain attacks.

Impact

Attackers who achieve code execution in a CI runner (via expression injection, fork checkout, compromised action, etc.) need a way to exfiltrate stolen secrets to infrastructure they control. The most common method is an HTTP POST request to an attacker-owned domain carrying environment variables, secret values, or tokens as the request body. The combination of external HTTP requests with secrets access in a workflow is a high-confidence indicator worth manual review.

Investigation note: the flagged step ("Wait for server readiness") polls /dev/tcp/127.0.0.1/4321 β€” a local docs preview server started earlier in the same job (npm run dev -- --host 0.0.0.0 --port 4321), not an external domain. This looks like a likely false positive from the rule's heuristic; there is no outbound HTTP request to an external domain in this step. Still worth confirming no secret material can reach this or nearby steps in the job.

Remediation

  • Confirm the job/step does not have unnecessary secrets exposure (scope secrets:/env: to only what's required).
  • If confirmed benign (localhost-only traffic to a server started in the same job), add a scoped runner-guard suppression with a justification comment so the rule stops flagging local loopback checks.

Detected by runner-guard v2.6.0 β€” CI/CD source-to-sink vulnerability scanner
Workflow run: https://github.com/github/gh-aw/actions/runs/31460155227

Generated by πŸ“Š Static Analysis Report Β· agent Β· 150.9 AIC Β· βŒ– 33.6 AIC Β· ⊞ 11K Β· β—·

  • expires on Aug 17, 2026, 9:25 PM UTC-08:00

Metadata

Metadata

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions