# GitHub Actions

Run zn checks in CI on every push and pull request.

Source: https://usezn.com/docs/integrations/github-actions/

Two useful gates: the self-test (proves the engine works in your runner) and `scan` (audits prompt templates, Markdown, skills and configs in your repo for injection traps).

```yaml
# .github/workflows/zn.yml
name: zn security checks
on: [push, pull_request]

jobs:
  zn:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: actions/setup-node@v4
        with:
          node-version: 20
      - name: Self-test
        run: npx -y zn-gate test
      - name: Scan prompts and agent configs
        run: npx -y zn-gate scan .
```

`scan` reads text and config files by default; add `--all` to include source code, or `--exclude fixtures` to skip test data. Both steps run offline with local rules and need no API key.
