github-actions[bot]
published Jul 8, 2026, 10:30 AM · updated Jul 8, 2026, 10:30 AM
Daily Runtime Threat Scan
Security analysis complete. Verdict: CLEAN. All curl calls target github.com or api.github.com only (hardcoded REPO="github/gh-aw"). GH_TOKEN is passed solely as an env var for the gh CLI — never echoed, logged, or embedded in any curl header/URL. No eval, base64, obfuscated blobs, or external domains found. Installation is user-space only ($HOME/.local/share/gh/extensions/), with SHA256 checksum verification by default. The script is consistent with a standard, production-quality GitHub Actions CLI setup action.
Generated from Daily Runtime Threat Scan · 492.6 AIC · ⊞ 36.4K · ◷