CI/CD Risk Analyzer
Analyze CI/CD pipelines for security risks and misconfigurations.
Last reviewed by the Radiatus Cloud team
Want this automated for your stack?
We build CI/CD, Kubernetes & IaC pipelines that scale.
Analyse a pipeline for security risks
CI/CD pipelines run with enough privilege that a misconfiguration can expose secrets or let untrusted code reach production. This analyser reviews a pipeline definition for the risks and misconfigurations that most often cause those outcomes, so you can address them in your own pipelines before they are exploited.
The risks that recur
Common problems include running untrusted pull-request code with access to secrets, granting build jobs more permission than they need, using third-party actions without pinning them to a fixed version, and leaking secrets into logs. The through-line is that a pipeline often trusts its inputs and dependencies more than it should, and tightening that trust is the core of pipeline security. Each risk maps to a concrete change in the configuration.
A defensive review, kept local
Analysing your own pipeline for these risks is standard operational security, and finding an issue in review beats finding it after a compromise that used your pipeline as the way in. The analysis runs entirely in your browser, so your configuration is never uploaded, which matters when it describes your own infrastructure.
Related tools
- CI/CD Security Gap Analyzer — Checklist based analyzer for CI/CD pipeline security gaps.
- Docker Security Scanner — A new tool extracted from the codebase.
- Terraform Scanner — A new tool extracted from the codebase.
- SQL Formatter — Format and indent SQL queries for readability. Handles joins, subqueries and CTEs, supports common dialects, and runs entirely in your browser.
Frequently Asked Questions
What makes a CI/CD pipeline risky?
It runs with high privilege and often trusts inputs and dependencies, so a misconfiguration can expose secrets or let untrusted code reach production.
Why is running pull-request code dangerous?
Because a pull request from an untrusted contributor can contain code that, if run with access to secrets, exfiltrates them. Such jobs should not have access to sensitive credentials.
How do over-broad permissions cause problems?
A job with more access than it needs gives an attacker who compromises it more to work with. Least privilege limits the blast radius of any compromise.
Is this analysing my live pipeline?
No. It reviews a pipeline definition you provide, helping you find and fix risks in your own configuration.
Is my pipeline uploaded?
No. The analysis runs entirely in your browser.
Privacy & Security
Analysis done locally.
About This Tool
This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.