gha-security-review

GitHub Actions security review

gha-security-review is Sentry's agent skill for auditing GitHub Actions workflows for attacks an outsider can run, such as pwn requests, expression injection and credential theft, with a concrete exploit for each finding.

Install GitHub Actions security review

Install this skill with the skills CLI

Terminal
npx skills add getsentry/skills --skill gha-security-review

Or, for Claude Code, add Sentry's plugin marketplace

Terminal
claude plugin marketplace add getsentry/skills

Then install the sentry-skills plugin, which holds all 28 skills

Terminal
claude plugin install sentry-skills@sentry-skills

Restart Claude Code after installing the plugin. Sentry's README says its skills were written for Sentry employees, so some carry Sentry conventions.

Or paste this into your coding agent: Install the agent skill gha-security-review from github.com/getsentry/skills. A skill can include scripts that run on your computer, so read its source first.

What GitHub Actions security review does

gha-security-review is an agent skill from Sentry that reviews GitHub Actions workflows, composite actions and the files they load. Its threat model is an outside attacker with no write access, who can open pull requests from forks, file issues and post comments. Anything that needs write access to exploit, such as workflow_dispatch inputs, is out of scope and not reported.

The gha-security-review skill checks eight classes of problem: pull_request_target workflows that run fork code, untrusted text such as PR titles or branch names expanded inside run steps, comment-triggered commands with no author check, long-lived tokens reachable by untrusted code, poisoned config files including AGENTS.md and CLAUDE.md read by AI agents in CI, unpinned third-party actions in privileged jobs, broad permissions, and self-hosted runners and caches.

Every high-confidence finding must name the entry point, the payload, how it runs, the impact and a short proof-of-concept sketch. If the agent cannot build all five, the finding is downgraded to needs verification, and theoretical issues are dropped. The attack patterns draw on a 2025 analysis of a real campaign against GitHub Actions.

When to use GitHub Actions security review

  • You use pull_request_target and want to know whether a fork can run code with your secrets.
  • You run an AI agent in CI and worry a pull request could inject instructions into it.
  • You want your workflows audited before making a private repository public.
  • A bot command triggered by comments runs in your workflows and you want it checked.

When to pick something else

  • Application code vulnerabilities: use security-review from the same repository.

Which agents GitHub Actions security review works in

Sentry documents GitHub Actions security review for Claude Code, Cursor, Cline, GitHub Copilot. The open skills CLI also installs it into 78 agents, including Claude Code, Codex, Cursor, Gemini CLI, GitHub Copilot, OpenCode (we listed it with the CLI on October 1, 2026). See where each agent looks for skills.

The SKILL.md lists Claude Code tool names in allowed-tools (Read, Grep, Glob, Bash, Task). Other agents ignore that line and use their own file and shell tools.

GitHub Actions security review license

GitHub Actions security review is published under Apache-2.0.

  • Differential review: differential-review is Trail of Bits' agent skill for security review of a pull request, commit or diff, using git history, blast radius counts and test coverage, and ending in a written markdown report. (7,328 repository stars on October 2, 2026)
  • Firebase security rules auditor: firebase-security-rules-auditor is the Firebase team's agent skill for auditing Firestore and Cloud Storage security rules for privilege escalation, update bypasses and missing limits, returning a 1 to 5 score in JSON. (462 repository stars on October 2, 2026)
  • Semgrep rule creator: semgrep-rule-creator is Trail of Bits' agent skill for writing custom Semgrep rules that detect vulnerabilities and bug patterns, test-first, with taint mode preferred and every test required to pass. (7,328 repository stars on October 2, 2026)
  • Supply chain risk auditor: supply-chain-risk-auditor is Trail of Bits' agent skill for auditing a project's npm, PyPI and Go dependencies for known advisories, abandoned upstreams, publisher concentration and install scripts, measured by bundled scripts. (7,328 repository stars on October 2, 2026)

More from Sentry

  • Code review: code-review is Sentry's agent skill for reviewing pull requests by Sentry's engineering practices: runtime errors, performance, side effects, compatibility, security, design, tests and the tone of feedback. (1,031 repository stars on October 2, 2026)
  • Iterate on PR: iterate-pr is Sentry's agent skill that keeps working on a GitHub pull request until CI passes and high and medium priority review comments are fixed, using bundled scripts and the gh CLI. (1,031 repository stars on October 2, 2026)
  • Security review: security-review is Sentry's agent skill for reviewing code for exploitable vulnerabilities, such as injection, XSS, broken access control and weak crypto, reporting only findings it has confirmed with high confidence. (1,031 repository stars on October 2, 2026)

Lists that include gha-security-review