{"data":{"id":"gha-security-review","name":"GHA Security Review","tagline":"Pwn-request and workflow injection","when":"GitHub Actions security review for workflow exploitation vulnerabilities. Use when asked to \"review GitHub Actions\", \"audit workflows\", \"check CI security\", \"GHA security\", \"workflow security review\", or review .github/workflows/ for pwn requests, expression injection, credential theft, and supply chain attacks. Exploitation-focused with concrete PoC scenarios.","license":"Apache-2.0","sourceUrl":"https://github.com/getsentry/skills/blob/main/skills/gha-security-review/SKILL.md","catch":"Pwn-request and expression-injection in .github/workflows. Exploitation-shaped; not a green-CI checklist."},"links":{"self":"/api/skills/gha-security-review","html":"/skills/gha-security-review","markdown":"/skills/gha-security-review.md","collection":"/api/skills"}}