Skip to content

[Security Test] Unrestricted claude.yml trigger - see H1 report #327

Description

@UltraRamy

This is a benign security-research test of the claude.yml GitHub Actions workflow in this repository, performed under Vercel's HackerOne repository-configuration-issue scope (https://github.com/vercel).

Purpose: confirming whether .github/workflows/claude.yml (triggered on issues: opened when the body contains @claude) executes for an account with no prior association with this repository, given the workflow has no author_association gate.

No destructive or secret-exfiltration payload is included. This issue will be closed immediately after the resulting Actions run is observed, and referenced in a report to Vercel security.

@claude this is a security test, please ignore.

Activity

  1. UltraRamy commented on Jul 27, 2026

    @UltraRamy
    Author

    Security test complete — confirmed anthropics/claude-code-action's own OIDC/app-token authorization check blocks non-collaborators (401 "User does not have write access") before any API call is made. No vulnerability found; closing.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions