Official agent skill

Gha Security Review

by getsentry in getsentry/skills

GitHub Actions security review for workflow exploitation vulnerabilities.

OfficialApache-2.0Auto-check: notesSecurity

Install Gha Security Review

skills CLI
$ npx skills add getsentry/skills --skill gha-security-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install getsentry/skills gha-security-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/getsentry/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/gha-security-review .claude/skills/gha-security-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
gha-security-review
GitHub stars
1k
Used in
3 other repos
Token cost
~2.2k tokens
SKILL.md length
941 words
Files
10 (incl. references)
Skills in repo
27
Repo updated
First seen
Licence
Apache-2.0

At a glance

GitHub Actions security review for workflow exploitation vulnerabilities.

  • Works in 4 steps: Classify Triggers and Load References → Check for Vulnerability Classes → Validate Before Reporting → …
  • Asked to review GitHub Actions
  • SKILL.md covers Scope, Threat Model, Confidence and Step 1: Classify Triggers and…, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Gha Security Review is an agent skill from getsentry/skills, published by the product's own GitHub organization. GitHub Actions security review for workflow exploitation vulnerabilities. Use when asked to "review GitHub Actions", "audit workflows", "check CI security", "GHA security", "workflow security review", or review .github/workflows/ for pwn requests, expression injection, credential theft, and supply chain attacks. Exploitation-focused with concrete PoC scenarios.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including reference files (for example `references/ai-prompt-injection-via-ci.md`, `references/comment-triggered-commands.md` and `references/credential-escalation.md`).

It sits in Security, covering Security review, CI/CD and Penetration testing. It works with GitHub Actions. The repository describes itself as: Agent Skills used by the Sentry team for development. The licence is Apache-2.0.

When your agent uses it

  • Asked to review GitHub Actions
  • Audit workflows
  • Check CI security
  • Workflow security review

Example prompts

  • “review GitHub Actions”
  • “audit workflows”
  • “check CI security”
  • “/gha-security-review”

Requirements

  • Pre-approved tools (allowed-tools): Read, Grep, Glob, Bash, Task

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Classify Triggers and Load References
  2. Check for Vulnerability Classes
  3. Validate Before Reporting
  4. Report Findings

What it can do on your machine

Read from SKILL.md and the folder at commit d18b7aa. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Glob
    • Bash
    • Task

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • stepsecurity.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Gha Security Review loads about 2.2k tokens when it runs, and up to ~19k if it reads all its reference files. Until then it costs about 96 tokens; SKILL.md has 941 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~96
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~19k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Grep, Glob, Bash, Task

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from getsentry/skills at commit d18b7aa, republished under its Apache-2.0 licence (© getsentry). 941 words, ~2,230 tokens.

Download SKILL.mdSave it as .claude/skills/gha-security-review/SKILL.md (or your agent's skills folder). This skill also uses 9 other files; get the full folder from GitHub.
name
gha-security-review
description
GitHub Actions security review for workflow exploitation vulnerabilities. Use when asked to "review GitHub Actions", "audit workflows", "check CI security", "GHA security", "workflow security review", or review .github/workflows/ for pwn requests, expression injection, credential theft, and supply chain attacks. Exploitation-focused with concrete PoC scenarios.
allowed-tools
Read, Grep, Glob, Bash, Task
<!--
Attack patterns and real-world examples sourced from the HackerBot Claw campaign analysis
by StepSecurity (2025): https://www.stepsecurity.io/blog/hackerbot-claw-github-actions-exploitation
-->

GitHub Actions Security Review

Find exploitable vulnerabilities in GitHub Actions workflows. Every finding MUST include a concrete exploitation scenario — if you can't build the attack, don't report it.

This skill encodes attack patterns from real GitHub Actions exploits — not generic CI/CD theory.

Scope

Review the workflows provided (file, diff, or repo). Research the codebase as needed to trace complete attack paths before reporting.

Files to Review
  • .github/workflows/*.yml — all workflow definitions
  • action.yml / action.yaml — composite actions in the repo
  • .github/actions/*/action.yml — local reusable actions
  • Config files loaded by workflows: CLAUDE.md, AGENTS.md, Makefile, shell scripts under .github/
Out of Scope
  • Workflows in other repositories (only note the dependency)
  • GitHub App installation permissions (note if relevant)

Threat Model

Only report vulnerabilities exploitable by an external attacker — someone without write access to the repository. The attacker can open PRs from forks, create issues, and post comments. They cannot push to branches, trigger workflow_dispatch, or trigger manual workflows.

Do not flag vulnerabilities that require write access to exploit:

  • workflow_dispatch input injection — requires write access to trigger
  • Expression injection in push-only workflows on protected branches
  • workflow_call input injection where all callers are internal
  • Secrets in workflow_dispatch/schedule-only workflows

Confidence

Report only HIGH and MEDIUM confidence findings. Do not report theoretical issues.

ConfidenceCriteriaAction
HIGHTraced the full attack path, confirmed exploitableReport with exploitation scenario and fix
MEDIUMAttack path partially confirmed, uncertain linkReport as needs verification
LOWTheoretical or mitigated elsewhereDo not report

For each HIGH finding, provide all five elements:

  1. Entry point — How does the attacker get in? (fork PR, issue comment, branch name, etc.)
  2. Payload — What does the attacker send? (actual code/YAML/input)
  3. Execution mechanism — How does the payload run? (expression expansion, checkout + script, etc.)
  4. Impact — What does the attacker gain? (token theft, code execution, repo write access)
  5. PoC sketch — Concrete steps an attacker would follow

If you cannot construct all five, report as MEDIUM (needs verification).


Step 1: Classify Triggers and Load References

For each workflow, identify triggers and load the appropriate reference:

Trigger / PatternLoad Reference
pull_request_targetreferences/pwn-request.md
issue_comment with command parsingreferences/comment-triggered-commands.md
${{ }} in run: blocksreferences/expression-injection.md
PATs / deploy keys / elevated credentialsreferences/credential-escalation.md
Checkout PR code + config file loadingreferences/ai-prompt-injection-via-ci.md
Third-party actions (especially unpinned)references/supply-chain.md
permissions: block or secrets usagereferences/permissions-and-secrets.md
Self-hosted runners, cache/artifact usagereferences/runner-infrastructure.md
Any confirmed findingreferences/real-world-attacks.md

Load references selectively — only what's relevant to the triggers found.

Step 2: Check for Vulnerability Classes

Check 1: Pwn Request

Does the workflow use pull_request_target AND check out fork code?

  • Look for actions/checkout with ref: pointing to PR head
  • Look for local actions (./.github/actions/) that would come from the fork
  • Check if any run: step executes code from the checked-out PR
Check 2: Expression Injection

Are ${{ }} expressions used inside run: blocks in externally-triggerable workflows?

  • Map every ${{ }} expression in every run: step
  • Confirm the value is attacker-controlled (PR title, branch name, comment body — not numeric IDs, SHAs, or repository names)
  • Confirm the expression is in a run: block, not if:, with:, or job-level env:
Check 3: Unauthorized Command Execution

Does an issue_comment-triggered workflow execute commands without authorization?

  • Is there an author_association check?
  • Can any GitHub user trigger the command?
  • Does the command handler also use injectable expressions?
Check 4: Credential Escalation

Are elevated credentials (PATs, deploy keys) accessible to untrusted code?

  • What's the blast radius of each secret?
  • Could a compromised workflow steal long-lived tokens?
Show full SKILL.md (384 more words)Show less
Check 5: Config File Poisoning

Does the workflow load configuration from PR-supplied files?

  • AI agent instructions: CLAUDE.md, AGENTS.md, .cursorrules
  • Build configuration: Makefile, shell scripts
Check 6: Supply Chain

Are third-party actions securely pinned to full SHAs?

  • Pin third-party / external actions and reusable workflows only
  • Do not flag first-party actions/* or github/* on version tags
  • Do not flag same-repo / vendored (./.github/actions/...) as supply-chain pinning issues
  • Only report when the job has secrets, OIDC, write token, release, deploy, package, or signing power — unprivileged read-only CI is not a finding
Check 7: Permissions and Secrets

Are workflow permissions minimal? Are secrets properly scoped?

Check 8: Runner Infrastructure

Are self-hosted runners, caches, or artifacts used securely?

Safe Patterns (Do Not Flag)

Before reporting, check if the pattern is actually safe:

PatternWhy Safe
pull_request_target WITHOUT checkout of fork codeNever executes attacker code
${{ github.event.pull_request.number }} in run:Numeric only — not injectable
${{ github.repository }} / github.repository_ownerRepo owner controls this
${{ secrets.* }}Not an expression injection vector
${{ }} in if: conditionsEvaluated by Actions runtime, not shell
${{ }} in with: inputsPassed as string parameters, not shell-evaluated
Third-party actions pinned to full SHAImmutable reference
First-party actions/* / github/* on version tagsOutside third-party pinning policy — do not flag
Same-repo / vendored local actionsNot third-party supply chain (review pwn-request separately)
pull_request trigger (not _target)Runs in fork context with read-only token
Any expression in workflow_dispatch/schedule/push to protected branchesRequires write access — outside threat model

Key distinction: ${{ }} is dangerous in run: blocks (shell expansion) but safe in if:, with:, and env: at the job/step level (Actions runtime evaluation).

Step 3: Validate Before Reporting

Before including any finding, read the actual workflow YAML and trace the complete attack path:

  1. Read the full workflow — don't rely on grep output alone
  2. Trace the trigger — confirm the event and check if: conditions that gate execution
  3. Trace the expression/checkout — confirm it's in a run: block or actually references fork code
  4. Confirm attacker control — verify the value maps to something an external attacker sets
  5. Check existing mitigations — env var wrapping, author_association checks, restricted permissions, SHA pinning

If any link is broken, mark MEDIUM (needs verification) or drop the finding.

If no checks produced a finding, report zero findings. Do not invent issues.

Step 4: Report Findings

markdown
## GitHub Actions Security Review

### Findings

#### [GHA-001] [Title] (Severity: Critical/High/Medium)
- **Workflow**: `.github/workflows/release.yml:15`
- **Trigger**: `pull_request_target`
- **Confidence**: HIGH — confirmed through attack path tracing
- **Exploitation Scenario**:
  1. [Step-by-step attack]
- **Impact**: [What attacker gains]
- **Fix**: [Code that fixes the issue]

### Needs Verification
[MEDIUM confidence items with explanation of what to verify]

### Reviewed and Cleared
[Workflows reviewed and confirmed safe]

If no findings: "No exploitable vulnerabilities identified. All workflows reviewed and cleared."

© getsentry, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 9 other files (references) in skills/gha-security-review of getsentry/skills.

  • SKILL.md
  • references/ai-prompt-injection-via-ci.md
  • references/comment-triggered-commands.md
  • references/credential-escalation.md
  • references/expression-injection.md
  • references/permissions-and-secrets.md
  • references/pwn-request.md
  • references/real-world-attacks.md
  • references/runner-infrastructure.md
  • references/supply-chain.md

Open the folder on GitHubat commit d18b7aa

Used in 3 other repositories

We found 12 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 3 other GitHub owners. This page covers the copy in getsentry/skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Gha Security Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Gha Security Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Gha Security Review this skillgetsentry/skills1k3 repos~2.2kAutomated safety check: NotesApache-2.0
Agentic GitHub Actions Auditortrailofbits/skills7.4k6 repos~5.4kAutomated safety check: NotesCC-BY-SA-4.0
Code Securitysemgrep/skills322—~1.2kAutomated safety check: PassCustom licence
Update Vulndbboostsecurityio/poutine522—~173Automated safety check: PassApache-2.0
Managing Pipelinesrileyhilliard/claude-essentials130—~1.5kAutomated safety check: PassMIT
Workflow Security Auditapache/magpie110—~3.8kAutomated safety check: PassApache-2.0

Similar skills

  • Official

    Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.

    7.4k GitHub starsUsed in 6 repos~5.4k tokens
    SecurityAuto-check: notes
  • Code Security

    semgrep/skills

    Official

    Security guidelines for writing secure code. An agent skill from semgrep/skills.

    322 GitHub stars~1.2k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Update Vulndb

    boostsecurityio/poutine

    Update the embedded build platform vulnerability database from the CVE Project's cvelistV5 repository.

    522 GitHub stars~173 tokensUpdated yesterday
    SecurityAuto-check passed
  • Managing Pipelines

    rileyhilliard/claude-essentials

    Guides GitHub Actions CI/CD architecture, security hardening, and deployment strategies.

    130 GitHub stars~1.5k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Read-only GitHub Actions workflow security audit for one repository, a repository set, or a whole GitHub org.

    110 GitHub stars~3.8k tokensUpdated today
    SecurityAuto-check passed
  • A skill your agent uses when editing, adding, or reviewing any file under .github/workflows/, or when a CI step installs a CLI tool (npm i -g, npx, pipx, uses: /setup-).

    1.1k GitHub stars~1.9k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed

More from getsentry/skills

All 27 skills in this repo
  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    Auto-check: warnings
  • Gh Review Requests

    getsentry/skills

    Official

    Fetch unread GitHub notifications for open PRs where review is requested from a specified team or opened by a team member.

    1k GitHub starsUsed in 3 repos~621 tokens
    Auto-check: notes
  • Security Review

    getsentry/skills

    Official

    Security code review for vulnerabilities. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.9k tokens
    Auto-check: notes
  • Skill Writer

    getsentry/skills

    Official

    Create, synthesize, and iteratively improve agent skills following the Agent Skills specification.

    1k GitHub stars~2.5k tokensUpdated 4 days ago
    Auto-check passed
  • Django Access Review

    getsentry/skills

    Official

    Django access control and IDOR security review. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 3 repos~2.6k tokens
    Auto-check: notes
  • Code Simplifier

    getsentry/skills

    Official

    Simplifies and refines code for clarity, consistency, and maintainability while preserving all functionality.

    1k GitHub starsUsed in 6 repos~991 tokens
    Auto-check passed

Works with

Categories

Questions about Gha Security Review

What does Gha Security Review do?

GitHub Actions security review for workflow exploitation vulnerabilities. Gha Security Review is an agent skill from getsentry/skills, published by the product's own GitHub organization. GitHub Actions security review for workflow exploitation vulnerabilities.

When should I use Gha Security Review?

Gha Security Review fits situations like: asked to review GitHub Actions; audit workflows; check CI security; workflow security review.

How do I install Gha Security Review in Claude Code?

Run `npx skills add getsentry/skills --skill gha-security-review -a claude-code`. Or copy the skill folder (skills/gha-security-review in getsentry/skills) into .claude/skills/gha-security-review in your project. Claude Code loads it when a task matches its description.

How do I install Gha Security Review in Codex?

Run `npx skills add getsentry/skills --skill gha-security-review -a codex`. Or copy the skill folder (skills/gha-security-review in getsentry/skills) into .agents/skills/gha-security-review in your project. Codex loads it when a task matches its description.

Can I use Gha Security Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add getsentry/skills --skill gha-security-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/gha-security-review, .gemini/skills/gha-security-review, .github/skills/gha-security-review and .opencode/skills/gha-security-review in your project.

What does Gha Security Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Gha Security Review is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Grep, Glob, Bash, Task.

Does Gha Security Review access the network?

SKILL.md names 1 domain. As links in the text: stepsecurity.io. This is read from the text; nothing was executed.

Is Gha Security Review safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Gha Security Review use?

Gha Security Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Gha Security Review use?

About 2.2k tokens (SKILL.md is roughly 8.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 17k tokens, read only when the agent opens those files.

What are the alternatives to Gha Security Review?

Skills that share tags, products or a category with Gha Security Review: Agentic GitHub Actions Auditor (trailofbits/skills, 7.4k stars), Code Security (semgrep/skills, 322 stars), Update Vulndb (boostsecurityio/poutine, 522 stars) and Managing Pipelines (rileyhilliard/claude-essentials, 130 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Gha Security Review?

getsentry (a GitHub organization, an official publisher) maintains it in getsentry/skills, which has 1,037 GitHub stars. The repository holds 27 skills in this directory. The repository was last updated on October 2, 2026.

Source: getsentry/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.