Stack Gems
Menu
← Skills

GHA Security Review

Pwn-request and workflow injection

Sentry · Apache-2.0

When

GitHub Actions security review for workflow exploitation vulnerabilities. Use when asked to "review GitHub Actions", "audit workflows", "check CI security", "GHA security", "workflow security review", or review .github/workflows/ for pwn requests, expression injection, credential theft, and supply chain attacks. Exploitation-focused with concrete PoC scenarios.

The Catch

Pwn-request and expression-injection in .github/workflows. Exploitation-shaped; not a green-CI checklist.

Embed

Reviewed on Stack Gems
[![Reviewed on Stack Gems](https://stackgems.com/badge/skill/gha-security-review.svg)](https://stackgems.com/skills/gha-security-review)