Key capabilities
- Parse multiple YAML workflows locally without executing expressions
- Review workflow and job token permissions with least privilege in mind
- Find untrusted event expressions used directly in shell scripts
- Export portable JSON, CSV, Markdown and SARIF findings
