GitHub Actions Security Review workflow skill. Use this skill when the user needs Find exploitable vulnerabilities in GitHub Actions workflows. Every finding MUST include a concrete exploitation scenario \u2014 if you can't build the attack, don't report it and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.