zizmor: Finding Template Injection and Token Risks in GitHub Actions
zizmor performs domain-specific static analysis on workflow and action YAML for template injection, broad permissions, artifact credential leaks, and unpinned uses; it does not analyze called shell scripts.