React Email Template Development
Build React-based email templates, preview them locally and review components, styling and localization.
Find exploitable vulnerabilities in GitHub Actions workflows. Every finding MUST include a concrete exploitation scenario — if you can't build the attack, don't report it.
This skill encodes attack patterns from real GitHub Actions exploits — not generic CI/CD theory.
Review the workflows provided (file, diff, or repo). Research the codebase as needed to trace complete attack paths before reporting.
.github/workflows/*.yml — all workflow definitionsaction.yml / action.yaml — composite actions in the repo.github/actions/*/action.yml — local reusable actionsCLAUDE.md, AGENTS.md, Makefile, shell scripts under .github/Only report vulnerabilities exploitable by an external attacker — someone without write access to the repository. The attacker can open PRs from forks, create issues, and post comments. They cannot push to branches, trigger workflow_dispatch, or trigger manual workflows.
Do not flag vulnerabilities that require write access to exploit:
- workflow_dispatch input injection — requires write access to trigger
- Expression injection in push-only workflows on protected branches
- workflow_call input injection where all callers are internal
- Secrets in workflow_dispatch/schedule-only workflows
Report only HIGH and MEDIUM confidence findings. Do not report theoretical issues.
| Confidence | Criteria | Action |
|---|---|---|
| HIGH | Traced the full attack path, confirmed exploitable | Report with exploitation scenario and fix |
| MEDIUM | Attack path partially confirmed, uncertain link | Report as needs verification |
| LOW | Theoretical or mitigated elsewhere | Do not report |
For each HIGH finding, provide all five elements:
If you cannot construct all five, report as MEDIUM (needs verification).
For each workflow, identify triggers and load the appropriate reference:
| Trigger / Pattern | Load Reference |
|---|---|
pull_request_target |
references/pwn-request.md |
issue_comment with command parsing |
references/comment-triggered-commands.md |
${{ }} in run: blocks |
references/expression-injection.md |
| PATs / deploy keys / elevated credentials | references/credential-escalation.md |
| Checkout PR code + config file loading | references/ai-prompt-injection-via-ci.md |
| Third-party actions (especially unpinned) | references/supply-chain.md |
permissions: block or secrets usage |
references/permissions-and-secrets.md |
| Self-hosted runners, cache/artifact usage | references/runner-infrastructure.md |
| Any confirmed finding | references/real-world-attacks.md |
Load references selectively — only what's relevant to the triggers found.
Does the workflow use pull_request_target AND check out fork code?
- Look for actions/checkout with ref: pointing to PR head
- Look for local actions (./.github/actions/) that would come from the fork
- Check if any run: step executes code from the checked-out PR
Are ${{ }} expressions used inside run: blocks in externally-triggerable workflows?
- Map every ${{ }} expression in every run: step
- Confirm the value is attacker-controlled (PR title, branch name, comment body — not numeric IDs, SHAs, or repository names)
- Confirm the expression is in a run: block, not if:, with:, or job-level env:
Does an issue_comment-triggered workflow execute commands without authorization?
- Is there an author_association check?
- Can any GitHub user trigger the command?
- Does the command handler also use injectable expressions?
Are elevated credentials (PATs, deploy keys) accessible to untrusted code? - What's the blast radius of each secret? - Could a compromised workflow steal long-lived tokens?
Does the workflow load configuration from PR-supplied files?
- AI agent instructions: CLAUDE.md, AGENTS.md, .cursorrules
- Build configuration: Makefile, shell scripts
Are third-party actions securely pinned to full SHAs?
- Pin third-party / external actions and reusable workflows only
- Do not flag first-party actions/* or github/* on version tags
- Do not flag same-repo / vendored (./.github/actions/...) as supply-chain pinning issues
- Only report when the job has secrets, OIDC, write token, release, deploy, package, or signing power — unprivileged read-only CI is not a finding
Are workflow permissions minimal? Are secrets properly scoped?
Are self-hosted runners, caches, or artifacts used securely?
Before reporting, check if the pattern is actually safe:
| Pattern | Why Safe |
|---|---|
pull_request_target WITHOUT checkout of fork code |
Never executes attacker code |
${{ github.event.pull_request.number }} in run: |
Numeric only — not injectable |
${{ github.repository }} / github.repository_owner |
Repo owner controls this |
${{ secrets.* }} |
Not an expression injection vector |
${{ }} in if: conditions |
Evaluated by Actions runtime, not shell |
${{ }} in with: inputs |
Passed as string parameters, not shell-evaluated |
| Third-party actions pinned to full SHA | Immutable reference |
First-party actions/* / github/* on version tags |
Outside third-party pinning policy — do not flag |
| Same-repo / vendored local actions | Not third-party supply chain (review pwn-request separately) |
pull_request trigger (not _target) |
Runs in fork context with read-only token |
Any expression in workflow_dispatch/schedule/push to protected branches |
Requires write access — outside threat model |
Key distinction: ${{ }} is dangerous in run: blocks (shell expansion) but safe in if:, with:, and env: at the job/step level (Actions runtime evaluation).
Before including any finding, read the actual workflow YAML and trace the complete attack path:
if: conditions that gate executionrun: block or actually references fork codeIf any link is broken, mark MEDIUM (needs verification) or drop the finding.
If no checks produced a finding, report zero findings. Do not invent issues.
## GitHub Actions Security Review
### Findings
#### [GHA-001] [Title] (Severity: Critical/High/Medium)
- **Workflow**: `.github/workflows/release.yml:15`
- **Trigger**: `pull_request_target`
- **Confidence**: HIGH — confirmed through attack path tracing
- **Exploitation Scenario**:
1. [Step-by-step attack]
- **Impact**: [What attacker gains]
- **Fix**: [Code that fixes the issue]
### Needs Verification
[MEDIUM confidence items with explanation of what to verify]
### Reviewed and Cleared
[Workflows reviewed and confirmed safe]
If no findings: "No exploitable vulnerabilities identified. All workflows reviewed and cleared."
Source: Sentry · Apache-2.0 · SHA-256 shown alongside the download.
License file included. A license and checksum are not a security certification. Review package instructions and scripts before running them.
getsentry-gha-security-review/SKILL.md9088 bytesAn adaptation record is bundled. Inspect the declared changes and archived original before use. Review adaptation and original-file hashes →
Machine-readable installation guide →Source and packaging checks recorded on 2026-10-03. These notes are not safety certification or measured task performance.
Access to workflow YAML, local actions, and relevant repository configuration; a client able to read and search project files.
Review only repositories you are authorized to inspect. Keep examples inert; do not run exploit payloads, expose tokens, or execute untrusted pull-request code. Agent review is not a security certification. Core frontmatter was adapted by BB Skills for the existing namespace directory; unchanged original SKILL.md is archived. This does not imply client execution was tested.
Upstream commit: d18b7aa8ba878354e5c348310230e652f7690f9c
Runtime status: not tested by this catalog. Configure your client and test the skill in your own environment.
Records are supplied by the site administrator and bound to a specific package. They are not third-party safety certification. This page does not execute skills.
No published scenario records yet. Resource availability and download counts do not imply measured task performance.
Be the first to share your experience.
Sign in to leave a review →Build React-based email templates, preview them locally and review components, styling and localization.
Inspect documented Resend CLI operations for email, domains, templates and account administration.
Plan transactional email, templates, delivery events and account operations with Resend SDK references.
1 current outcome record · Read scope
Reference for the Claude API / Anthropic SDK — model ids, pricing, params, streaming, tool use, MCP, agents, caching, token counting, model …