github-actions

Fail

Audited by Runlayer on Mar 5, 2026

Risk Level: HIGH
Scan Summary
Max Score
91%
Files
5
Flagged
3
Chunks
6
Flagged Files (3)
github-actions/references/gha-workflow-and-downloads.mdHIGH
90.9%

Malicious tool definition detected

Tool: github-actions/references/gha-workflow-and-downloads.md [2/2] Description: -L \ -H "Authorization: Bearer $GITHUB_TOKEN" \ -H "Accept: application/vnd.github+json" \ "https://api.github.com/repos/<owner>/<repo>/actions/artifacts/<artifact-id>/zip" \ -o artifact.zip ``` ## Common Pitfalls - Forgetting to set `permissions.actions: read` for API-driven artifact listing.

github-actions/SKILL.mdLOW
60.9%

Tool passed security scan

github-actions/references/gha-ios-composite-action.mdLOW
52.1%

Tool passed security scan

Passed Files (2)Click to expand
github-actions/agents/openai.yamlOK
48.5%

Tool passed security scan

github-actions/references/gha-android-composite-action.mdOK
32.5%

Tool passed security scan

Audit Metadata
Max File Score
91%
Classification
UNKNOWN_SERVER
Files Scanned
5
Files Flagged
3
Chunks Analyzed
6
Analyzed
Mar 5, 2026, 05:43 PM
Security Audit — runlayer — github-actions