# GHA Security Review

> Pwn-request and workflow injection

**Subcategory:** Sentry  
**License:** Apache-2.0  
**Source:** https://github.com/getsentry/skills/blob/main/skills/gha-security-review/SKILL.md

---

## When it is useful

GitHub Actions security review for workflow exploitation vulnerabilities. Use when asked to "review GitHub Actions", "audit workflows", "check CI security", "GHA security", "workflow security review", or review .github/workflows/ for pwn requests, expression injection, credential theft, and supply chain attacks. Exploitation-focused with concrete PoC scenarios.

## The Catch

Pwn-request and expression-injection in .github/workflows. Exploitation-shaped; not a green-CI checklist.
