workflow-auditRun the audit

For teams running GitHub Actions

Find out what's quietly broken in your CI before it costs you a release.

Point it at a public repo. In a few minutes you get a report on duplicate workflows, scripts your workflows reference that no longer exist, and scheduled jobs that have been silently failing.

Run the audit — $19

One-time. Results in minutes. No account required.

Real example, not a mockup

We ran this on actions/checkout — GitHub's own repository

workflow-audit report — actions/checkout

✓ Workflows found: 7

✓ Duplicate workflows: none

✓ Dead script references: none

⚠ codeql-analysis.yml (schedule: 28 9 * * 0): 2 of last 5 runs failed

That failing schedule was real, and findable in about a minute — no one had to go digging for it.

How it works

Enter a public repo

owner/repo or a full GitHub URL. That's the only input.

We check it, deterministically

Every workflow file is parsed and compared. Findings come from that analysis, not from a model guessing.

You get a plain-language report

An AI-written summary sits on top of the findings — it never adds new claims.

What gets checked

Duplicate workflows

Workflows with near-identical steps, flagged so you know before you maintain the same fix in two places.

Dead script references

A workflow calling scripts/deploy.sh that was deleted months ago fails silently until someone needs it.

Schedule health

Workflows with a cron trigger are checked against real run history — not just whether the YAML looks correct.

Before you paste a repo in

  • Public repositories only — nothing private is ever read.
  • No GitHub login, no OAuth, no write access requested, ever.
  • The written summary is generated by AI (Claude), grounded strictly in the checks above — it does not invent findings, guarantees, or dollar-savings estimates.
  • Every check is disclosed in the report itself, including anything it couldn't verify.

Get your report

$19, one-time

Public repos only, for now.

Public repositories only. No GitHub login, no write access.

Questions

Do you store my code?

We read workflow YAML files and check whether referenced paths exist — we don't clone or retain your repository. The report itself is kept so you can revisit it.

What if my repo is private?

Not supported yet. Public repos only, for this first version.

What if it finds nothing?

Then you get a short report saying so — that's a real, useful answer, not a reason to manufacture a finding.