Agentic GitHub Actions Auditor
trailofbits/skills
Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.
GitHub Actions security review for workflow exploitation vulnerabilities.
$ npx skills add getsentry/skills --skill gha-security-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install getsentry/skills gha-security-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/getsentry/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/gha-security-review .claude/skills/gha-security-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "gha-security-review" agent skill from https://github.com/getsentry/skills/tree/main/skills/gha-security-review into .claude/skills/gha-security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gha-security-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/getsentry/skills/tree/main/skills/gha-security-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add getsentry/skills --skill gha-security-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install getsentry/skills gha-security-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/getsentry/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/gha-security-review .agents/skills/gha-security-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "gha-security-review" agent skill from https://github.com/getsentry/skills/tree/main/skills/gha-security-review into .agents/skills/gha-security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gha-security-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add getsentry/skills --skill gha-security-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install getsentry/skills gha-security-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/getsentry/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/gha-security-review .cursor/skills/gha-security-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "gha-security-review" agent skill from https://github.com/getsentry/skills/tree/main/skills/gha-security-review into .cursor/skills/gha-security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gha-security-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/getsentry/skills.git --path skills/gha-security-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add getsentry/skills --skill gha-security-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install getsentry/skills gha-security-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/getsentry/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/gha-security-review .gemini/skills/gha-security-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "gha-security-review" agent skill from https://github.com/getsentry/skills/tree/main/skills/gha-security-review into .gemini/skills/gha-security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gha-security-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install getsentry/skills gha-security-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add getsentry/skills --skill gha-security-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/getsentry/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/gha-security-review .github/skills/gha-security-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "gha-security-review" agent skill from https://github.com/getsentry/skills/tree/main/skills/gha-security-review into .github/skills/gha-security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gha-security-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add getsentry/skills --skill gha-security-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install getsentry/skills gha-security-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/getsentry/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/gha-security-review .opencode/skills/gha-security-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "gha-security-review" agent skill from https://github.com/getsentry/skills/tree/main/skills/gha-security-review into .opencode/skills/gha-security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gha-security-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
gha-security-reviewGitHub Actions security review for workflow exploitation vulnerabilities.
Gha Security Review is an agent skill from getsentry/skills, published by the product's own GitHub organization. GitHub Actions security review for workflow exploitation vulnerabilities. Use when asked to "review GitHub Actions", "audit workflows", "check CI security", "GHA security", "workflow security review", or review .github/workflows/ for pwn requests, expression injection, credential theft, and supply chain attacks. Exploitation-focused with concrete PoC scenarios.
Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including reference files (for example `references/ai-prompt-injection-via-ci.md`, `references/comment-triggered-commands.md` and `references/credential-escalation.md`).
It sits in Security, covering Security review, CI/CD and Penetration testing. It works with GitHub Actions. The repository describes itself as: Agent Skills used by the Sentry team for development. The licence is Apache-2.0.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit d18b7aa. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadGrepGlobBashTaskFrom allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
stepsecurity.ioFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Gha Security Review loads about 2.2k tokens when it runs, and up to ~19k if it reads all its reference files. Until then it costs about 96 tokens; SKILL.md has 941 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Read, Grep, Glob, Bash, TaskAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from getsentry/skills at commit d18b7aa, republished under its Apache-2.0 licence (© getsentry). 941 words, ~2,230 tokens.
.claude/skills/gha-security-review/SKILL.md (or your agent's skills folder). This skill also uses 9 other files; get the full folder from GitHub.<!--
Attack patterns and real-world examples sourced from the HackerBot Claw campaign analysis
by StepSecurity (2025): https://www.stepsecurity.io/blog/hackerbot-claw-github-actions-exploitation
-->
Find exploitable vulnerabilities in GitHub Actions workflows. Every finding MUST include a concrete exploitation scenario — if you can't build the attack, don't report it.
This skill encodes attack patterns from real GitHub Actions exploits — not generic CI/CD theory.
Review the workflows provided (file, diff, or repo). Research the codebase as needed to trace complete attack paths before reporting.
.github/workflows/*.yml — all workflow definitionsaction.yml / action.yaml — composite actions in the repo.github/actions/*/action.yml — local reusable actionsCLAUDE.md, AGENTS.md, Makefile, shell scripts under .github/Only report vulnerabilities exploitable by an external attacker — someone without write access to the repository. The attacker can open PRs from forks, create issues, and post comments. They cannot push to branches, trigger workflow_dispatch, or trigger manual workflows.
Do not flag vulnerabilities that require write access to exploit:
workflow_dispatch input injection — requires write access to triggerpush-only workflows on protected branchesworkflow_call input injection where all callers are internalworkflow_dispatch/schedule-only workflowsReport only HIGH and MEDIUM confidence findings. Do not report theoretical issues.
| Confidence | Criteria | Action |
|---|---|---|
| HIGH | Traced the full attack path, confirmed exploitable | Report with exploitation scenario and fix |
| MEDIUM | Attack path partially confirmed, uncertain link | Report as needs verification |
| LOW | Theoretical or mitigated elsewhere | Do not report |
For each HIGH finding, provide all five elements:
If you cannot construct all five, report as MEDIUM (needs verification).
For each workflow, identify triggers and load the appropriate reference:
| Trigger / Pattern | Load Reference |
|---|---|
pull_request_target | references/pwn-request.md |
issue_comment with command parsing | references/comment-triggered-commands.md |
${{ }} in run: blocks | references/expression-injection.md |
| PATs / deploy keys / elevated credentials | references/credential-escalation.md |
| Checkout PR code + config file loading | references/ai-prompt-injection-via-ci.md |
| Third-party actions (especially unpinned) | references/supply-chain.md |
permissions: block or secrets usage | references/permissions-and-secrets.md |
| Self-hosted runners, cache/artifact usage | references/runner-infrastructure.md |
| Any confirmed finding | references/real-world-attacks.md |
Load references selectively — only what's relevant to the triggers found.
Does the workflow use pull_request_target AND check out fork code?
actions/checkout with ref: pointing to PR head./.github/actions/) that would come from the forkrun: step executes code from the checked-out PRAre ${{ }} expressions used inside run: blocks in externally-triggerable workflows?
${{ }} expression in every run: steprun: block, not if:, with:, or job-level env:Does an issue_comment-triggered workflow execute commands without authorization?
author_association check?Are elevated credentials (PATs, deploy keys) accessible to untrusted code?
Does the workflow load configuration from PR-supplied files?
CLAUDE.md, AGENTS.md, .cursorrulesMakefile, shell scriptsAre third-party actions securely pinned to full SHAs?
actions/* or github/* on version tags./.github/actions/...) as supply-chain pinning issuesAre workflow permissions minimal? Are secrets properly scoped?
Are self-hosted runners, caches, or artifacts used securely?
Before reporting, check if the pattern is actually safe:
| Pattern | Why Safe |
|---|---|
pull_request_target WITHOUT checkout of fork code | Never executes attacker code |
${{ github.event.pull_request.number }} in run: | Numeric only — not injectable |
${{ github.repository }} / github.repository_owner | Repo owner controls this |
${{ secrets.* }} | Not an expression injection vector |
${{ }} in if: conditions | Evaluated by Actions runtime, not shell |
${{ }} in with: inputs | Passed as string parameters, not shell-evaluated |
| Third-party actions pinned to full SHA | Immutable reference |
First-party actions/* / github/* on version tags | Outside third-party pinning policy — do not flag |
| Same-repo / vendored local actions | Not third-party supply chain (review pwn-request separately) |
pull_request trigger (not _target) | Runs in fork context with read-only token |
Any expression in workflow_dispatch/schedule/push to protected branches | Requires write access — outside threat model |
Key distinction: ${{ }} is dangerous in run: blocks (shell expansion) but safe in if:, with:, and env: at the job/step level (Actions runtime evaluation).
Before including any finding, read the actual workflow YAML and trace the complete attack path:
if: conditions that gate executionrun: block or actually references fork codeIf any link is broken, mark MEDIUM (needs verification) or drop the finding.
If no checks produced a finding, report zero findings. Do not invent issues.
## GitHub Actions Security Review
### Findings
#### [GHA-001] [Title] (Severity: Critical/High/Medium)
- **Workflow**: `.github/workflows/release.yml:15`
- **Trigger**: `pull_request_target`
- **Confidence**: HIGH — confirmed through attack path tracing
- **Exploitation Scenario**:
1. [Step-by-step attack]
- **Impact**: [What attacker gains]
- **Fix**: [Code that fixes the issue]
### Needs Verification
[MEDIUM confidence items with explanation of what to verify]
### Reviewed and Cleared
[Workflows reviewed and confirmed safe]If no findings: "No exploitable vulnerabilities identified. All workflows reviewed and cleared."
© getsentry, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 9 other files (references) in skills/gha-security-review of getsentry/skills.
Open the folder on GitHubat commit d18b7aa
We found 12 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 3 other GitHub owners. This page covers the copy in getsentry/skills, which our catalogue first saw on October 7, 2026.
Gha Security Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Gha Security Review this skillgetsentry/skills | 1k | 3 repos | ~2.2k | Automated safety check: Notes | Apache-2.0 | |
| Agentic GitHub Actions Auditortrailofbits/skills | 7.4k | 6 repos | ~5.4k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Code Securitysemgrep/skills | 322 | — | ~1.2k | Automated safety check: Pass | Custom licence | |
| Update Vulndbboostsecurityio/poutine | 522 | — | ~173 | Automated safety check: Pass | Apache-2.0 | |
| Managing Pipelinesrileyhilliard/claude-essentials | 130 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Workflow Security Auditapache/magpie | 110 | — | ~3.8k | Automated safety check: Pass | Apache-2.0 |
trailofbits/skills
Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.
semgrep/skills
Security guidelines for writing secure code. An agent skill from semgrep/skills.
boostsecurityio/poutine
Update the embedded build platform vulnerability database from the CVE Project's cvelistV5 repository.
rileyhilliard/claude-essentials
Guides GitHub Actions CI/CD architecture, security hardening, and deployment strategies.
apache/magpie
Read-only GitHub Actions workflow security audit for one repository, a repository set, or a whole GitHub org.
asyncapi/generator
A skill your agent uses when editing, adding, or reviewing any file under .github/workflows/, or when a CI step installs a CLI tool (npm i -g, npx, pipx, uses: /setup-).
getsentry/skills
Scan agent skills for security issues. An agent skill from getsentry/skills.
getsentry/skills
Fetch unread GitHub notifications for open PRs where review is requested from a specified team or opened by a team member.
getsentry/skills
Security code review for vulnerabilities. An agent skill from getsentry/skills.
getsentry/skills
Create, synthesize, and iteratively improve agent skills following the Agent Skills specification.
getsentry/skills
Django access control and IDOR security review. An agent skill from getsentry/skills.
getsentry/skills
Simplifies and refines code for clarity, consistency, and maintainability while preserving all functionality.
Works with
Categories
GitHub Actions security review for workflow exploitation vulnerabilities. Gha Security Review is an agent skill from getsentry/skills, published by the product's own GitHub organization. GitHub Actions security review for workflow exploitation vulnerabilities.
Gha Security Review fits situations like: asked to review GitHub Actions; audit workflows; check CI security; workflow security review.
Run `npx skills add getsentry/skills --skill gha-security-review -a claude-code`. Or copy the skill folder (skills/gha-security-review in getsentry/skills) into .claude/skills/gha-security-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add getsentry/skills --skill gha-security-review -a codex`. Or copy the skill folder (skills/gha-security-review in getsentry/skills) into .agents/skills/gha-security-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add getsentry/skills --skill gha-security-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/gha-security-review, .gemini/skills/gha-security-review, .github/skills/gha-security-review and .opencode/skills/gha-security-review in your project.
SKILL.md names no scripts, command-line tools or credentials: Gha Security Review is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Grep, Glob, Bash, Task.
SKILL.md names 1 domain. As links in the text: stepsecurity.io. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Gha Security Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.2k tokens (SKILL.md is roughly 8.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 17k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Gha Security Review: Agentic GitHub Actions Auditor (trailofbits/skills, 7.4k stars), Code Security (semgrep/skills, 322 stars), Update Vulndb (boostsecurityio/poutine, 522 stars) and Managing Pipelines (rileyhilliard/claude-essentials, 130 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
getsentry (a GitHub organization, an official publisher) maintains it in getsentry/skills, which has 1,037 GitHub stars. The repository holds 27 skills in this directory. The repository was last updated on October 2, 2026.
Source: getsentry/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.