github-actions[bot]
published Jun 19, 2026, 5:07 PM · updated Jun 19, 2026, 5:07 PM
Daily Runtime Threat Scan
Scan complete — focus area: setup-cli/. Files scanned: action.yml, install.sh, install_test.sh. No hidden files found. All 3 independent judges returned clean (3/3 consensus). The install script only makes network calls to github.com and api.github.com to download the gh-aw binary with SHA256 verification. GH_TOKEN is passed only as an ambient env var for the gh CLI and is never read or transmitted by the script. No obfuscation, eval, exfiltration, persistence, or privilege escalation detected. Next round-robin focus_index advanced to 0 (setup/).
Generated from Daily Runtime Threat Scan · 196.7 AIC · ⊞ 36.4K · ◷