---
title: "gha-security-review skill: audit GitHub Actions workflows"
canonical_url: https://cookiesforai.app/skills/getsentry/gha-security-review
last_updated: 2026-10-02T01:58:30+02:00
type: skill
summary: "gha-security-review is Sentry's agent skill for auditing GitHub Actions workflows for attacks an outsider can run, such as pwn requests, expression injection and credential theft, with a concrete exploit for each finding."
install: "npx skills add getsentry/skills --skill gha-security-review"
related:
  - "https://cookiesforai.app/skills/trailofbits/differential-review"
  - "https://cookiesforai.app/skills/firebase/firebase-security-rules-auditor"
  - "https://cookiesforai.app/skills/trailofbits/semgrep-rule-creator"
  - "https://cookiesforai.app/skills/trailofbits/supply-chain-risk-auditor"
  - "https://cookiesforai.app/skills/getsentry/code-review"
  - "https://cookiesforai.app/skills/getsentry/iterate-pr"
  - "https://cookiesforai.app/skills/getsentry/security-review"
---

# GitHub Actions security review

gha-security-review is Sentry's agent skill for auditing GitHub Actions workflows for attacks an outsider can run, such as pwn requests, expression injection and credential theft, with a concrete exploit for each finding.

| Fact | Value |
|---|---|
| Publisher | Sentry (official, own GitHub account) |
| Source | https://github.com/getsentry/skills/tree/HEAD/skills/gha-security-review |
| License | Apache-2.0 |
| Repository stars | 1,031 on 2026-10-02 |
| Skill name | gha-security-review |
| Category | Security |
| Skill last changed | 2026-09-29 |
| Page updated | 2026-10-02 |
| Facts checked | 2026-10-02 |

## Install

Install this skill with the skills CLI:

```
npx skills add getsentry/skills --skill gha-security-review
```

Or, for Claude Code, add Sentry's plugin marketplace:

```
claude plugin marketplace add getsentry/skills
```

Then install the sentry-skills plugin, which holds all 28 skills:

```
claude plugin install sentry-skills@sentry-skills
```

Restart Claude Code after installing the plugin. Sentry's README says its skills were written for Sentry employees, so some carry Sentry conventions.

## Ask your coding agent

A skill can include scripts that run on your computer, so read its source first: https://github.com/getsentry/skills/tree/HEAD/skills/gha-security-review

```text
Install the agent skill gha-security-review from github.com/getsentry/skills.
```

## What it does

gha-security-review is an agent skill from Sentry that reviews GitHub Actions workflows, composite actions and the files they load. Its threat model is an outside attacker with no write access, who can open pull requests from forks, file issues and post comments. Anything that needs write access to exploit, such as workflow_dispatch inputs, is out of scope and not reported.

The gha-security-review skill checks eight classes of problem: pull_request_target workflows that run fork code, untrusted text such as PR titles or branch names expanded inside run steps, comment-triggered commands with no author check, long-lived tokens reachable by untrusted code, poisoned config files including AGENTS.md and CLAUDE.md read by AI agents in CI, unpinned third-party actions in privileged jobs, broad permissions, and self-hosted runners and caches.

Every high-confidence finding must name the entry point, the payload, how it runs, the impact and a short proof-of-concept sketch. If the agent cannot build all five, the finding is downgraded to needs verification, and theoretical issues are dropped. The attack patterns draw on a 2025 analysis of a real campaign against GitHub Actions.

## When to use it

- You use pull_request_target and want to know whether a fork can run code with your secrets.
- You run an AI agent in CI and worry a pull request could inject instructions into it.
- You want your workflows audited before making a private repository public.
- A bot command triggered by comments runs in your workflows and you want it checked.

## When to pick something else

- Application code vulnerabilities: use security-review from the same repository.

## Which agents it works in

Sentry documents it for Claude Code, Cursor, Cline, GitHub Copilot. The open skills CLI also installs it into 78 agents (listed with the CLI on 2026-10-01).

The SKILL.md lists Claude Code tool names in allowed-tools (Read, Grep, Glob, Bash, Task). Other agents ignore that line and use their own file and shell tools.

## License

Apache-2.0.

## Related

### Related skills for security

- [Differential review](https://cookiesforai.app/skills/trailofbits/differential-review): differential-review is Trail of Bits' agent skill for security review of a pull request, commit or diff, using git history, blast radius counts and test coverage, and ending in a written markdown report.
- [Firebase security rules auditor](https://cookiesforai.app/skills/firebase/firebase-security-rules-auditor): firebase-security-rules-auditor is the Firebase team's agent skill for auditing Firestore and Cloud Storage security rules for privilege escalation, update bypasses and missing limits, returning a 1 to 5 score in JSON.
- [Semgrep rule creator](https://cookiesforai.app/skills/trailofbits/semgrep-rule-creator): semgrep-rule-creator is Trail of Bits' agent skill for writing custom Semgrep rules that detect vulnerabilities and bug patterns, test-first, with taint mode preferred and every test required to pass.
- [Supply chain risk auditor](https://cookiesforai.app/skills/trailofbits/supply-chain-risk-auditor): supply-chain-risk-auditor is Trail of Bits' agent skill for auditing a project's npm, PyPI and Go dependencies for known advisories, abandoned upstreams, publisher concentration and install scripts, measured by bundled scripts.

### More from Sentry

- [Code review](https://cookiesforai.app/skills/getsentry/code-review): code-review is Sentry's agent skill for reviewing pull requests by Sentry's engineering practices: runtime errors, performance, side effects, compatibility, security, design, tests and the tone of feedback.
- [Iterate on PR](https://cookiesforai.app/skills/getsentry/iterate-pr): iterate-pr is Sentry's agent skill that keeps working on a GitHub pull request until CI passes and high and medium priority review comments are fixed, using bundled scripts and the gh CLI.
- [Security review](https://cookiesforai.app/skills/getsentry/security-review): security-review is Sentry's agent skill for reviewing code for exploitable vulnerabilities, such as injection, XSS, broken access control and weak crypto, reporting only findings it has confirmed with high confidence.

