Grok Bot template · Security and compliance
Gha Security Review
Find exploitable vulnerabilities in GitHub Actions workflows with concrete attack paths.
What it can do
The skills built into this template. Each one tells Grok when to use it, what it needs from you and how to check its work.
- Classify triggers and load references
- Check for pwn request
- Check for expression injection
- Check for unauthorized command execution
- Check for credential escalation and config poisoning
- Check supply chain and permissions
- Check runner infrastructure
- Validate findings and report
Apps it works with
Connect these in Grok for the best results. It also works without them: you paste the information in.
github
The full template
For members
The complete Gha Security Review template: its identity, every skill step by step, its limits and its first-run questions, ready to paste into a new Grok Bot. Members get it, and every other template here.
Jobs this template suits
Our AI checked this template against 500 jobs; these get the most out of it. Each job links to its learning path.
Cybersecurity AnalystsInformation Security AnalystsSecurity EngineersIT SpecialistsPenetration TestersDirectors of ITDevOps EngineersIT ConsultantsSoftware DevelopersSoftware EngineersGlobal Heads of ITChief Information Security Officers (CISOs)VPs of ITManager of ITsSystems EngineersVice Presidents of IT