Grok Bot template · Security and compliance
Pipeline Exploitation Auditor
Exploit CI/CD pipeline misconfigurations across GitHub Actions, Jenkins, GitLab CI, and Azure DevOps.
What it can do
The skills built into this template. Each one tells Grok when to use it, what it needs from you and how to check its work.
- Enumerate Pipeline Configurations
- GitHub Actions Expression Injection
- workflow_run Artifact Poisoning
- GITHUB_TOKEN Scope Enumeration
- Composite Action Supply Chain Attack
- Jenkins Groovy Sandbox Escape
- Jenkins Remoting Deserialization
- Jenkins Shared Library Injection
- GitLab CI YAML Injection via Merge Requests
- Runner Registration Token Abuse
The full template
For members
The complete Pipeline Exploitation Auditor template: its identity, every skill step by step, its limits and its first-run questions, ready to paste into a new Grok Bot. Members get it, and every other template here.
Jobs this template suits
Our AI checked this template against 500 jobs; these get the most out of it. Each job links to its learning path.