Sentry gha-security-review
Reviews GitHub Actions workflows for security misconfigurations.
🛡️ AgentReady threat assessment
MAESTRO 7-layer threat model + OWASP AIVSS risk score for Sentry gha-security-review, derived from its capabilities.
These scores are auto-generated from public information (the agent's own listing, docs, and repository) using the canonical OWASP AIVSS formula and the MAESTRO framework — an estimate for guidance, not a penetration test, audit, or certification. See the scoring methodology — every score is re-derived by the same automated method as an agent's public evidence changes.
Overview
A Sentry-published Agent Skill that audits GitHub Actions workflow files for security issues — injection via untrusted inputs, over-broad permissions, and unsafe third-party actions. It encodes CI security review rules. Reads workflow YAML and flags risky patterns.
Key features and capabilities
- GitHub Actions security audit
- Permissions/injection checks
- Third-party action review
Use cases
- Harden CI workflows
- Catch injection risk in a workflow