October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk5 min

How to Secure a Manual Claude Code PR Review in GitHub Actions

A secure manual Claude Code review workflow uses a narrow PR trigger, protected credentials, least-privilege permissions, and a clear plan for forked contributions.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To run Claude Code reviews manually in GitHub Actions, add a pull-request workflow that calls anthropics/claude-code-action@v1, store its credential as a GitHub secret, and grant only the permissions the review actually needs. Treat the workflow as review assistance—not an automatic merge gate—and decide in advance what should happen with forked pull requests, which do not receive ordinary repository secrets.

What a manual Claude Code review workflow does

Claude Code’s GitHub Action runs inside a repository’s GitHub Actions workflow. A checked-in YAML file can start it for selected pull-request events and provide a review prompt. This differs from Anthropic’s separate automatic Claude Code Review feature and from cloud-hosted Claude Code sessions. Manual setup requires repository administrator access. See Anthropic’s GitHub Actions documentation.

As an Amazon Associate I earn from qualifying purchases.

Anthropic’s documented review example checks out the repository, installs the code-review plugin, and passes a review prompt to the Action. It uses anthropics/claude-code-action@v1 and listens for pull requests that are opened, synchronized with new commits, marked ready for review, or reopened. The example skips draft and closed pull requests, pull requests judged not to need review, and pull requests that already have a Claude comment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

There are two Action modes: without a prompt, it waits for a trigger phrase (by default, @claude); with a prompt, it runs automatically when a configured workflow event occurs. For a predictable manual PR review, make both the event trigger and review prompt explicit in the workflow file.

Set up the workflow and credential

  1. Install the GitHub App. Install Anthropic’s Claude GitHub App, or create and install a custom app if your organization needs a narrower installation permission set. You need repository administrator access for manual setup.
  2. Add an authentication credential. Store an ANTHROPIC_API_KEY or, where appropriate, a CLAUDE_CODE_OAUTH_TOKEN as a GitHub Actions secret. Never put either value directly in the workflow file or commit it to the repository. Anthropic also documents OIDC federation for supported enterprise provider routes.
  3. Add a workflow file. Put the YAML under .github/workflows/ and configure its pull-request events, job permissions, credential input, checkout, plugin installation, and review prompt. Use Anthropic’s current example as the starting point rather than copying an older beta configuration unchanged.
  4. Choose where findings appear. Without explicit comment configuration, findings are available in the workflow run log. Anthropic’s inline-comment example includes --comment in the prompt and allows mcp__github_inline_comment__create_inline_comment through claude_args. Confirm the permissions required by the comment integration before enabling it.

Separate App permissions from workflow-token permissions

The Claude GitHub App’s installation permissions and the workflow’s GITHUB_TOKEN permissions are separate controls. Limiting one does not automatically narrow the other.

Anthropic says its standard GitHub App uses a shared permission set for multiple Claude features, which cannot be reduced at installation. It includes read/write access to Actions, Checks, Contents, Discussions, Issues, Pull requests, repository hooks, and Workflows, plus read access to Members, Metadata, and Statuses. For organizations that require a narrower installation, Anthropic documents a custom GitHub App with Contents, Issues, and Pull requests.

Separately, set the workflow or job’s permissions to the minimum the task needs. The documented review example grants read access to contents, pull requests, and issues, plus id-token: write for the Action’s default GitHub App authentication. Do not add write access simply because another example posts comments; check the live requirements for the output method you enable. GitHub explains token scoping in its GITHUB_TOKEN guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Plan for fork pull requests and secret access

GitHub does not pass ordinary repository secrets to workflows triggered by pull requests from forks in public repositories. As a result, a secret-based Claude review workflow will not authenticate for those contributions. GitHub also does not automatically forward secrets to reusable workflows. See GitHub’s secrets guidance.

Choose a deliberate policy for fork contributions, such as having a maintainer trigger a review through a trusted path. Do not expose a privileged credential to untrusted pull-request code merely to make the workflow run for every contributor. OIDC can be an alternative where the cloud or enterprise authentication route supports it; confirm that the provider and workflow are configured for that model.

Limit triggers and prevent unnecessary runs

Keep event filters narrow so the workflow runs only when a review is useful. The Action checks the triggering actor: for issue and pull-request events, the user generally needs repository write access unless exceptions are configured. It rejects bot actors by default to reduce automation loops; any named exceptions require explicit configuration.

If you use mention-driven behavior instead of an automatic prompt, filter for the intended comment phrase. This keeps unrelated comments from starting runs and consuming runner time or model usage. Decide which pull-request states and events matter to your review process instead of enabling a broad trigger by default.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Choose output and keep a human in the merge decision

Workflow logs and PR comments serve different needs. Logs keep findings in the run record; inline comments put them beside relevant code, but require explicit prompt and tool configuration. Make the intended output clear to maintainers so they know where to look.

Anthropic advises: “Grant the workflow only the permissions it needs, and review Claude’s changes before merging.” Its documentation does not establish a guaranteed defect-detection rate or independent review-accuracy measure. Treat findings as suggestions to assess alongside your normal human review and branch-protection process.

Keep the Action configuration current

Anthropic’s current examples use anthropics/claude-code-action@v1. For older beta workflows, Anthropic says to replace @beta with @v1, remove the old mode input, replace direct_prompt with prompt, and move CLI settings such as max_turns and model into claude_args.

Action inputs, examples, permissions, and model defaults can change. Recheck the official documentation before upgrading. The documentation does not prescribe a pinned commit SHA; teams with supply-chain requirements should choose and verify their own action-pinning policy.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Account for usage without assuming a fixed price

Each run uses GitHub Actions minutes and model tokens. Consumption varies with the prompt and response length, task complexity, and codebase size, so the documentation does not establish a stable per-review price. Anthropic says OAuth-authenticated runs use the subscription rather than API billing.

For organizations routing inference through other platforms, Anthropic documents Amazon Bedrock, Google Cloud Agent Platform, and Microsoft Foundry integrations using OIDC identity federation. Availability and configuration depend on the applicable provider route.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.