What changed, and why it matters
This commit adds a GitHub Actions workflow that lets people summon an AI assistant named Claude by mentioning '@claude' in issue or pull-request comments. It only reads repository contents, issues, pull requests, and CI results; it does not modify code or have dangerous permissions. There is no direct security vulnerability visible in the change itself.
No immediate security action is required. As a routine hardening step, maintainers should review the Anthropic action's permissions and token handling, pin the action to a specific SHA rather than a floating major tag, and monitor for any future permission escalation in the workflow.
Security signals we found
New GitHub Actions workflow introduced
Uses third-party action from Anthropic (anthropics/claude-code-action@v1)
Triggers on issue/PR comments and review bodies containing '@claude'
Permissions are read-only for contents, issues, pull-requests, and actions
id-token:write granted for OIDC authentication to Claude service
No code-write or deployment permissions requested
Evidence from the diff
The commit introduces .github/workflows/claude.yml, a new workflow triggered by issue/PR comments, issues, and PR reviews containing ‘@claude’. It runs the official anthropic/claude-code-action@v1 with read-only permissions for contents, pull-requests, issues, and actions, plus id-token:write for OIDC authentication. The workflow fetches only the latest commit (fetch-depth: 1) and passes a repository secret. No write permissions to code, packages, or deployments are granted, and no shell commands or user-controlled inputs are executed directly.
Changed components
.github/workflows/claude.ymlInspect captured patch +50 / −0
diff --git a/.github/workflows/claude.yml b/.github/workflows/claude.yml
new file mode 100644
index 0000000..d300267
--- /dev/null
+++ b/.github/workflows/claude.yml
@@ -0,0 +1,50 @@
+name: Claude Code
+
+on:
+ issue_comment:
+ types: [created]
+ pull_request_review_comment:
+ types: [created]
+ issues:
+ types: [opened, assigned]
+ pull_request_review:
+ types: [submitted]
+
+jobs:
+ claude:
+ if: |
+ (github.event_name == 'issue_comment' && contains(github.event.comment.body, '@claude')) ||
+ (github.event_name == 'pull_request_review_comment' && contains(github.event.comment.body, '@claude')) ||
+ (github.event_name == 'pull_request_review' && contains(github.event.review.body, '@claude')) ||
+ (github.event_name == 'issues' && (contains(github.event.issue.body, '@claude') || contains(github.event.issue.title, '@claude')))
+ runs-on: ubuntu-latest
+ permissions:
+ contents: read
+ pull-requests: read
+ issues: read
+ id-token: write
+ actions: read # Required for Claude to read CI results on PRs
+ steps:
+ - name: Checkout repository
+ uses: actions/checkout@v4
+ with:
+ fetch-depth: 1
+
+ - name: Run Claude Code
+ id: claude
+ uses: anthropics/claude-code-action@v1
+ with:
+ claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }}
+
+ # This is an optional setting that allows Claude to read CI results on PRs
+ additional_permissions: |
+ actions: read
+
+ # Optional: Give a custom prompt to Claude. If this is not specified, Claude will perform the instructions specified in the comment that tagged it.
+ # prompt: 'Update the pull request description to include a summary of changes.'
+
+ # Optional: Add claude_args to customize behavior and configuration
+ # See https://github.com/anthropics/claude-code-action/blob/main/docs/usage.md
+ # or https://code.claude.com/docs/en/cli-reference for available options
+ # claude_args: '--allowed-tools Bash(gh pr:*)'
+
Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.