The change enters the normal repository review process.
Action-path lab
Trace how an AI-assisted PR can reach a publishing credential.
This simulation follows a PR that can modify release.yml, whose job can use NPM_TOKEN to publish a package. Export the result as an Agent Action BOM, JSON workflow path, or evidence packet.
The PR can alter a job that runs after merge.
The job can use the token to publish a package.
Check which approval, if any, applies before the job can use NPM_TOKEN.
What does this lab export? A simulated Agent Action BOM, JSON action path, and evidence packet showing how normal AI-assisted software delivery can move through repos, CI/CD, tools, credentials, targets, approvals, and evidence gaps. It does not access your repo or upload source.
Choose one workflow. The graph will show where credential reach appears.
Step 1
Pick a workflow to trace
Start with the path your team might already trust because it begins as ordinary engineering work.
Step 2
Label the AI tool
This personalizes the simulated graph and BOM. The capabilities below determine the action path.
Step 3
What can this workflow reach?
Prechecked items are the default assumptions for this scenario. Toggle them to match your workflow.
Adjust path assumptions optional
Workflow trace
Credentialed CI/CD path
Next step
Map the same action path in one real workflow.
The simulation uses the same object Clyra maps in real workflows: actor, credential, action, target, approval, and evidence. Bring one PR, workflow file, agent instruction file, MCP config, package script, or release path to map the action boundary, owner, credential scope, approval point, and evidence trail without uploading source to start.