PR Security Review

Review changed files for security risk, secret handling and auth issues, then comment on the PR.

Workflow preview

Drag to pan, click a step to center it, or use the controls to fit and zoom.

Loading workflow preview…
  1. GitHub PR webhook
  2. Fetch PR metadata
  3. Fetch changed files
  4. AI security review
  5. Human approval
  6. Comment PR
  7. End

What this workflow does

Review changed files for security risk, secret handling and auth issues, then comment on the PR. Catch security-sensitive review areas before risky pull requests are merged.

Trigger
PR opened or updated Start when a GitHub pull request is opened, updated, or tested manually.
Primary output
Post security comment 3 configured workflow actions

Template details

Category

Engineering & IT

Workflow includes
Best for

Security-conscious engineering teams

Before you use it

The template will guide you through these setup items in the workflow builder.

  1. 1 Connect GitHub
  2. 2 Pick or create a security-focused agent
  3. 3 Test against a real pull request
  4. 4 Review and approve the generated security comment