github-actions
Fail
Audited by Runlayer on Mar 5, 2026
Risk Level: HIGH
Scan Summary
Flagged Files (3)
github-actions/references/gha-workflow-and-downloads.mdHIGH
90.9%
Malicious tool definition detected
Tool: github-actions/references/gha-workflow-and-downloads.md [2/2] Description: -L \ -H "Authorization: Bearer $GITHUB_TOKEN" \ -H "Accept: application/vnd.github+json" \ "https://api.github.com/repos/<owner>/<repo>/actions/artifacts/<artifact-id>/zip" \ -o artifact.zip ``` ## Common Pitfalls - Forgetting to set `permissions.actions: read` for API-driven artifact listing.
github-actions/SKILL.mdLOW
60.9%
Tool passed security scan
github-actions/references/gha-ios-composite-action.mdLOW
52.1%
Tool passed security scan
Passed Files (2)Click to expand
github-actions/agents/openai.yamlOK
48.5%
Tool passed security scan
github-actions/references/gha-android-composite-action.mdOK
32.5%
Tool passed security scan
Audit Metadata