Skip to content
@skaldlab

Skald Lab

Skald Lab is an independent software studio focused on practical security for teams that ship on GitHub.

🐦‍⬛ Skald Lab

Security tooling that fits how teams already ship.

We build open-source security tools for the modern GitHub workflow — broad coverage, no per-seat pricing, and nothing leaves your repo.

Website · Muninn · Marketplace · @skaldlab


Our work

🐦‍⬛ Muninn — all-in-one CI/CD security scanner

CI CodeQL Release License: AGPL v3 Marketplace

One GitHub Action orchestrates eight best-in-class open-source scanners — gitleaks, zizmor, actionlint, poutine, semgrep, osv-scanner, trivy, checkov — normalizes their output into a single finding schema, and reports back as PR comments, SARIF, or JSON.

- uses: skaldlab/muninn@v0.3.3
  with:
    token: ${{ secrets.GITHUB_TOKEN }}

Secrets · SAST · CI/CD pipeline security · supply chain · dependencies · containers · IaC — in one line.


Why we build this way

  • Open source first — AGPL-3.0 core, self-hostable, trust through transparency.
  • Your code stays put — scans run on your own runner; nothing is uploaded to us.
  • CI/CD-native — built for GitHub Actions, results land in the Security tab automatically.
  • Zero config to start — works out of the box, tune it later when you want to.

The name

In Norse myth, a skald was a poet who kept and retold the stories that mattered. Muninn ("Memory") was one of Odin's two ravens, sent out each day to observe the world and return with what it learned. Our tools are named in that spirit — they watch, remember, and report back.

Get in touch

Made in Montevideo 🇺🇾 · AGPL-3.0 · Named after Odin's raven of Memory

Pinned Loading

  1. muninn muninn Public

    🐦‍⬛ Security scanner for GitHub Actions pipelines

    Go 18

Repositories

Showing 2 of 2 repositories

People

This organization has no public members. You must be a member to see who’s a part of this organization.

Top languages

Loading…

Most used topics

Loading…