github/gh-aw-actions

Durable reports produced for this repository by centrally managed packages.

Reports

21 Open 164 Resolved

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup-cli/. Files inspected: action.yml, install.sh, install.ps1. No threats found — all files are standard install scripts that download the gh-aw binary from official github/gh-aw GitHub releases with SHA256 checksum verification. No secret exfiltration, obfuscation, or unexpected network calls detected. Next focus area: setup/ (index 0).

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup/. Result: clean. All outbound HTTP limited to github.com releases with SHA256 verification; OIDC token exchange is for OTLP telemetry with proper secret masking; no hidden files, crypto mining, or exfiltration patterns detected. State advanced to focusindex=1 (setup-cli/ for next run). Judge gpt-4o verdict: clean.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup/ (round-robin index 0). Scanned 595+ files across setup/action.yml, setup/index.js, setup/setup.sh, setup/post.js, setup/clean.sh, setup/js/, and setup/sh/. No credible threats found. All suspicious patterns (base64, crypto, childprocess, curl, secret env var access) were contextually appropriate for a setup/install action. LLM-as-judge: 2/3 sub-agents (claude-sonnet, gpt-4.1) returned clean verdicts; o3 returned empty response. Cache state updated, next scan will focus on setup-cli/.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup-cli/. Files inspected: action.yml, install.sh, install.ps1. All 3 LLM judges (gpt-4.1, gemini-2.5-pro, claude security-review) returned clean. No threats found — all network calls are scoped to github.com/api.github.com, GHTOKEN is used only for GitHub API auth, and SHA256 checksum verification is present. State advanced to focusindex=0 (setup/) for next run.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup/ (index 0). Scanned action.yml, setup.sh, all 300 JS files in js/, 80 shell scripts in sh/, and md/ templates. No credible threats found. All outbound network calls (curl for binary installs, OTLP telemetry, local health checks) are consistent with documented setup/install behavior. Token handling properly uses secret masking. No exfiltration, obfuscated payloads, crypto mining, or persistence mechanisms detected. State advanced to focusindex=1 (setup-cli/) for next run.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup-cli/. Files inspected: action.yml, install.sh, install.ps1. All 3 LLM judges (claude-sonnet-4-5, gpt-4.1, gemini-2.5-flash) returned clean verdict. Code is consistent with a legitimate CLI installer: downloads only from github.com/api.github.com, verifies SHA256 checksums, uses GHTOKEN only as an auth header, no obfuscation or secret exfiltration. Next focusindex set to 0 (setup/).

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup-cli/. Scanned action.yml, install.sh, install.ps1. All files implement standard gh-aw CLI installation: downloads binary from github/gh-aw releases, validates SHA256 checksums, verifies binary execution. No secret exfiltration, obfuscation, suspicious network calls, or malicious behavior detected. Result: clean. Next focusindex set to 0 (setup/).

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup/ (round-robin index 0). Result: clean. Scanned all JavaScript (.cjs), shell scripts (.sh), action.yml, and index.js files. No threats found. All network calls are expected setup/install behavior (GitHub releases with SHA256 verification, optional OTLP telemetry). No obfuscation, mining, persistence, or exfiltration patterns detected. Three independent judges (claude-sonnet-4.6, gpt-4.1, primary agent) all returned clean. Next run will scan: setup-cli/.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup/. Scanned all shell scripts (setup/sh/), JavaScript files (setup/js/), and action metadata. Key files reviewed: exchangeotlpworkloadidentity.cjs (GCP WIF for OTLP telemetry — clean), validatesecrets.cjs (first-party API probing only — clean), memorycustomvalidation.cjs (sandboxed operator hook with secrets stripped from env — clean). All 3 independent judges returned verdict: clean. No hidden files, obfuscation blobs, or crypto miners found. Next focus index set to 1 (setup-cli/).

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup-cli/. Inspected action.yml, install.sh, install.ps1. All 3 LLM judges returned clean — scripts are standard CLI installers downloading from official github/gh-aw releases with SHA256 checksum verification. No threats found. Next focus: setup/ (index 0).

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete — focus area: setup/. No credible threats found. All 3 LLM judges returned "clean". The setup/ action copies JS/shell files for workflow orchestration, uses tokens only for GitHub API calls, and OTLP telemetry is opt-in only. Next scan will cover setup-cli/. Run note written to /tmp/gh-aw/cache-memory/runtime-threat-scan/runs/run-2026-08-19-21-18-19-853.md.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup-cli/. Files scanned: action.yml, install.sh, install.ps1. All 3 independent security judges returned clean — no secret exfiltration, unexpected outbound connections, obfuscated code, or privilege escalation found. Next scan will focus on setup/.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete for focus area: setup/. Scanned all files in setup/ (action.yml, index.js, setup.sh, 200+ .cjs scripts, 70+ .sh scripts). Two of three LLM judges (gpt-4.1, claude-sonnet) independently returned clean verdict. No secret exfiltration, suspicious eval usage, hidden files, or unrelated payloads found. Round-robin state advanced to focusindex=1 (setup-cli/) for next run. Run note recorded at /tmp/gh-aw/cache-memory/runtime-threat-scan/runs/.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete — focus area: setup-cli/. Inspected action.yml, install.sh, install.ps1. All 3 independent security judges returned clean. The action is a standard CLI installer: downloads gh-aw binary from github.com/github/gh-aw releases with SHA256 checksum verification, uses GHTOKEN only for GitHub API auth against github.com/api.github.com. No exfiltration, obfuscation, third-party network calls, or persistence mechanisms found. Next focusindex set to 0 (setup/).

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup/. No credible threats found. Reviewed action.yml, setup.sh, post.js, shell install scripts (installawfbinary.sh, installcopilotcli.sh, installghcli.sh, sudodockersbxinstall.sh, sudogvisorinstall.sh), and key JS files. All outbound network calls are consistent with documented setup/install behavior (downloads from github.com/releases with SHA256 checksum verification, health checks to localhost). No exfiltration, obfuscation, crypto mining, or persistence found. Next run will scan setup-cli/.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete — focus area: setup/. No credible threats found. All curl downloads target github.com official releases (github/gh-aw-firewall, github/gh-aw-threat-detection) and get.docker.com. base64 usage follows standard Git API patterns. OTLP token exchange targets Google STS for telemetry only, with proper secret masking. No exfiltration, obfuscation, or unexpected persistence detected. State advanced to focusindex=1 (next run: setup-cli/).

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup-cli/. Files scanned: action.yml, install.sh, install.ps1. All 3 LLM judges (claude-sonnet-4.6, gpt-4.1, o4-mini) returned clean. No threats found — scripts only contact github.com/api.github.com, perform SHA256 checksum verification, and follow standard GitHub Actions installer patterns. State updated to focusindex=0 for next run.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete — focus area: setup-cli/. Scanned action.yml, install.sh, install.ps1. All 3 independent judges returned clean. No threats found: downloads are from github.com releases only, SHA256 checksum verification is present, GHTOKEN used only for GitHub API auth, no obfuscation or exfiltration detected. State advanced to focusindex=0 (setup/) for next run.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup/. No credible threats found. Inspected action.yml, index.js, setup.sh, install scripts, OTLP telemetry, and JS runtime files. All network calls go to GitHub releases with SHA256 checksum verification. No hidden files, obfuscated code, or exfiltration patterns. Next run will scan setup-cli/ (focusindex advanced to 1).

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup-cli/ (action.yml, install.sh, install.ps1). All 3 independent security judges returned clean verdict. Scripts perform standard CLI install: download gh-aw binary from github.com releases, verify SHA256 checksum, install to /.local/share/gh/extensions/gh-aw. GHTOKEN used only for GitHub API authorization. No exfiltration, obfuscation, or suspicious behavior detected. Next run will scan setup/.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete for focus area setup/. All 3 independent judges (general-purpose, explore, security-review) unanimously returned clean. No suspicious code detected: network activity is limited to github.com/gvisor.dev downloads with checksum verification, localhost health checks, and opt-in user-configured OTLP telemetry. No hardcoded exfiltration endpoints, eval/obfuscation patterns, or credential forwarding found. State updated to focusindex=1 (next run will scan setup-cli/).

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup-cli/. Files inspected: action.yml, install.sh, install.ps1. All files are standard gh-aw CLI install scripts downloading binaries from official GitHub releases (github/gh-aw) with SHA256 checksum verification. No threats found — clean result. State advanced to focusindex=0 (setup/ next run).

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup-cli/. Scanned action.yml, install.sh, and install.ps1. All 3 files show standard installer behavior: binary download from github.com releases, SHA256 checksum verification, install to /.local/share/gh/extensions/gh-aw/, GHTOKEN used only for GitHub API auth. 2/3 judges returned clean verdict. No credible threats found.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Verdict: clean All behaviors in the setup/ directory are consistent with a legitimate shared GitHub Action. Binary installations use SHA256 checksum verification against official GitHub releases. Token handling is defensive (OAuth rejection) and scoped exclusively to same-origin GitHub authentication — no exfiltration paths. The OTLP telemetry path requires an explicit opt-in via OTELEXPORTEROTLPENDPOINT and uses standard Google Workload Identity Federation (OIDC token exchange via sts.googleapis.com) with a justified @safe-outputs-exempt annotation. External network destinations are limited to github.com, cli.github.com, googleapis.com, and standard Ubuntu APT r...

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup-cli/ (index 1). Scanned action.yml, install.sh, install.ps1. All 3 LLM judges returned clean — no threats found. The action performs standard gh-aw CLI installation from github.com/github/gh-aw releases with SHA256 checksum validation and no exfiltration. State advanced to focusindex=0 for next run.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup/. Result: clean. No credible threats found. All network calls are legitimate (GitHub API, Google STS/IAM for OTLP telemetry, models.dev for pricing). Token handling follows standard GitHub Actions patterns with proper masking. No exfiltration, obfuscation, hidden binaries, or persistence detected. Cache state updated; next run will scan setup-cli/.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup-cli/. Scanned action.yml, install.sh, install.ps1. All 3 LLM judges returned clean verdict. The action downloads the gh-aw binary exclusively from official github.com/github/gh-aw releases with SHA256 checksum verification — no secret exfiltration, obfuscation, persistence, or suspicious network calls detected. State advanced to focusindex=0 (setup/) for next run.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup/. Result: CLEAN. Scanned 554 files including shell scripts, JavaScript/CJS files, and action metadata. No suspicious patterns found: no token exfiltration, no obfuscated code, no crypto mining, no unexpected binaries or hidden files. All binary downloads are from github.com/github/ releases with SHA256 verification. 2/3 LLM judges returned clean verdicts (gemini-2.5-flash timed out). State updated to focusindex=1 (next run will scan setup-cli/).

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup/. Result: clean. All files in setup/ are consistent with a legitimate GitHub Actions setup action for the gh-aw agentic workflow system — file copying, OTLP telemetry, GitHub API handlers, MCP transport, and cleanup scripts. No exfiltration, obfuscation, unrelated payloads, or suspicious behavior found. 2/2 responsive LLM judges (claude-sonnet-4.6, gpt-4.1) independently agreed: clean. Next run will scan setup-cli/.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup-cli/. Files inspected: action.yml, install.sh, install.ps1. All files are clean standard CLI installer scripts — download gh-aw binary from GitHub releases with SHA256 checksum verification, use GHTOKEN legitimately for GitHub API auth, no exfiltration, obfuscation, or unrelated network behavior detected. Next scan will focus on setup/.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup-cli/. Files scanned: action.yml, install.sh, install.ps1. Result: clean. All network calls go only to github.com/api.github.com, SHA256 checksum verification is enabled by default, no secret exfiltration, no obfuscation. No credible threat found. Next focus index set to 0 (setup/).

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup/. No threats found. All files are consistent with expected setup/install action behavior: setup.sh copies JS/shell files to RUNNERTEMP, index.js sends OTLP spans, network calls are to GitHub APIs/releases with checksum verification. No exfiltration, obfuscated payloads, hidden binaries, or suspicious patterns detected. Next scan will cover setup-cli/.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete for focus area: setup/. No credible threats found. Scanned action.yml, index.js, post.js, setup.sh, all sh/ scripts (50 files), and js/.cjs files (200+ files). All network calls are legitimate: binary downloads from GitHub releases with SHA256 checksum verification, localhost MCP server health checks, and user-configured OTLP telemetry endpoints. No exfiltration, obfuscation, crypto mining, persistence mechanisms, or unauthorized secret access detected. Next scan will focus on setup-cli/ (focusindex updated to 1).

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup-cli/. Files inspected: action.yml, install.sh, install.ps1. All 3 LLM judges returned clean. No threats found. Binary downloads are scoped to github.com/github/gh-aw releases, SHA256 checksum verified, GHTOKEN used only for standard GitHub auth. State advanced to next focus area: setup/ (index 0).

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete for focus area setup/. Scanned all files in setup/ (action.yml, index.js, post.js, setup.sh, 200+ .cjs JS files, 50 .sh shell scripts, markdown prompts). Two independent sub-agent judges both returned clean verdicts. No suspicious code found: all network calls are bounded (OTLP to user-configured endpoints, binary downloads from first-party repo with SHA256 verification, localhost MCP health checks). No exfiltration, obfuscation, or unrelated payloads detected. State advanced to focusindex=1 (setup-cli/ is next).

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup/. Result: clean. No suspicious patterns found — all network calls target github.com/githubusercontent or local MCP gateway; credential scripts explicitly protect against exfiltration. Next run will scan setup-cli/.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete — focus area: setup-cli/. Inspected action.yml, install.sh, and install.ps1. All files are standard installer scripts downloading the gh-aw binary from github.com/github/gh-aw releases with SHA256 checksum verification. No suspicious behavior detected. Next focus: setup/. Cache state updated.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup-cli/. Inspected action.yml, install.sh, install.ps1. All files are clean — standard installer behavior downloading gh-aw binary from github/gh-aw releases with SHA256 checksum verification. No suspicious network calls, exfiltration, obfuscation, or unrelated behavior detected. State advanced to focusindex=0 (setup/) for next run.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup/. Scanned 546 files including action.yml, index.js, setup.sh, install scripts, and JS/shell runtime files. All 3 independent judges (claude-sonnet-4.6, gpt-4.1, o3-mini) returned clean verdicts. No threats found: no obfuscated code, no exfiltration patterns, no hidden binaries, no crypto mining indicators. State advanced to focusindex=1 (setup-cli/ for next run). Run note written to cache-memory.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup-cli/ (focusindex=1). Inspected: action.yml, install.sh, install.ps1. All 3 independent LLM judges returned CLEAN — scripts legitimately download the gh-aw binary from github/gh-aw releases with SHA256 checksum verification. GHTOKEN only flows to github.com/api.github.com. No exfiltration, obfuscation, or suspicious behavior found. Next run will scan: setup/ (focusindex=0).

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup-cli/. Inspected action.yml, install.sh, install.ps1. Both LLM judges returned "clean" — all code exhibits standard installer behavior: binary downloads exclusively from github.com/github/gh-aw/releases with SHA256 checksum verification, GHTOKEN used only for GitHub API auth, no obfuscation/exfiltration/persistence. State updated: next scan will cover setup/.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup/ (round-robin index 0). Scanned 545 files (379 .cjs scripts). No credible threats found. All curl usage is legitimate tool installation from github.com releases with SHA256 verification. Base64 usage is standard git auth encoding and GitHub API response decoding. OTLP telemetry properly redacts sensitive keys before transmission. No hidden files, obfuscated blobs, or exfiltration patterns detected. One sub-agent verdict: gpt-4.1=clean (two other models returned empty responses). State advanced to focusindex=1 (setup-cli/) for next run.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup/. Result: CLEAN. All 3 independent LLM judges (general-purpose, explore, security-review) returned clean. No credible threats found — all code is consistent with legitimate setup/install action behavior: tool installs from GitHub releases and GCS with SHA256 checksum verification, OTLP telemetry to user-configured endpoints only, GITHUBTOKEN used exclusively for GitHub API, no obfuscated payloads, no hardcoded exfiltration endpoints, no hidden files. State advanced to focusindex=1 (next scan: setup-cli/).

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup-cli/ (index 1). Inspected action.yml, install.sh, install.ps1. All files perform standard setup/install behavior — downloading gh-aw binary from official GitHub releases with SHA256 checksum verification. No threats detected. Next run will focus on setup/ (index 0).

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup/. No credible threats found. All 230 files inspected — shell scripts, JavaScript/CJS modules, and markdown templates. Network calls are all legitimate (GitHub API, GitHub releases downloads with checksum verification, AI provider APIs). No exfiltration patterns, obfuscation, hidden files, or suspicious payloads detected. Cache state advanced to focusindex=1 (setup-cli/ for next run).

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete for focus area setup/. No credible threats found. All 544 files scanned: external HTTP calls limited to github.com/api.github.com, OTLP telemetry is user-configured (opt-in), base64 used only for git auth headers and GitHub API content decoding, shell execution limited to git commands, no eval/obfuscation/hidden files. Three judges (claude-sonnet-4.6, gpt-4.1, o3) returned clean/clean/no-response. State updated: next scan will cover setup-cli/.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup/. No credible threats found. All 3 independent judges returned clean. Behaviors observed (binary installs with checksums, localhost MCP gateway management, opt-in OTLP telemetry, standard git auth, credential cleanup) are consistent with expected setup/install action behavior. Next scan will focus on setup-cli/. State updated: focusindex → 1.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup-cli/. Inspected action.yml, install.sh, install.ps1. All files are legitimate installer scripts — network calls limited to github.com/api.github.com for binary download and checksum verification, SHA256 validation performed, no exfiltration or obfuscation detected. Result: clean. Next run will scan setup/.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Security review complete. Verdict: clean. The setup/ action shows no indicators of compromise — no exfiltration, no obfuscation, no unauthorized persistence, and all network calls are scoped to user-configured or well-known official endpoints.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup/ (542 files). All 3 independent judges returned clean verdict. No suspicious patterns found: network calls scoped to github.com releases and storage.googleapis.com, checksums verified on all binary downloads, no exfiltration/obfuscation/persistence/mining. State updated: next focusindex = 1 (setup-cli/).

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup-cli/. Files inspected: action.yml, install.sh, install.ps1. All 3 LLM judges returned clean — standard CLI installer downloading gh-aw binary from github.com releases with SHA256 checksum verification, no secret exfiltration, no persistence, no obfuscation. Next focusindex: 0 (setup/).

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup/. Scanned 541 files including shell scripts, JS/CJS files, YAML, and action metadata. Three independent judges evaluated findings (installantigravitycli.sh GCS binary download, .bak test file, token handling, validatesecrets external calls). Verdicts: 2x clean (Sonnet, Gemini), 1x threat (GPT-4.1 — supply chain concern over GCS download). Escalation threshold not met (requires 2+ agreeing). No credible threat found. Next scan will cover setup-cli/.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete for focus area: setup/. No threats found. All JS, shell, and YAML files are consistent with expected setup/install action behavior. Binary installs use SHA256 verification. OTLP telemetry is opt-in. No exfiltration, crypto mining, hidden files, obfuscated blobs, or persistence patterns detected. Next focus area: setup-cli/ (index 1).

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup-cli/ (focusindex=1). Inspected 3 files: action.yml, install.sh, install.ps1. All 3 independent LLM judges returned clean. The scripts implement standard binary installer behavior: download gh-aw from github.com/github/gh-aw, SHA256 checksum verification, install to standard gh extension path, output version via GITHUBOUTPUT. No exfiltration, no obfuscation, no persistence, no suspicious network calls. State advanced to focusindex=0 (next run: setup/).

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete — focus area: setup-cli/. Inspected action.yml, install.sh, install.ps1. All 3 independent security judges returned clean. Files perform standard binary install from github/gh-aw releases with SHA256 verification, GHTOKEN scoped to GitHub API only, no exfiltration or suspicious behavior. State updated: next focusindex = 0 (setup/).

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete — focus area: setup/. Deep inspection of 200+ JavaScript (.cjs), shell (.sh), YAML, and JSON files found no credible threats. All network activity is accounted for (localhost health checks, GitHub release downloads with SHA256 verification, user-configured OTLP telemetry). No eval(), no encoded payloads, no crypto mining, no persistence, no exfiltration patterns. Three independent judge sub-agents unanimously returned clean. Next run will focus on setup-cli/. Run note written to cache-memory.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup/ (focusindex=0, next=1). Result: CLEAN. All 3 independent judges returned clean. No exfiltration, obfuscated payloads, crypto mining, persistence, or unauthorized secret forwarding detected. Outbound network calls are limited to user-configured OTLP telemetry endpoints and legitimate vendor APIs (GitHub, Anthropic, OpenAI) for diagnostic purposes only. Run note written to cache-memory.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup/. No threats found. All network calls in install scripts (installcopilotcli.sh, installawfbinary.sh, installantigravitycli.sh, installthreatdetectbinary.sh) target github.com/githubusercontent.com with SHA256 checksum verification. No exfiltration patterns, hidden files, obfuscated payloads, or suspicious behavior detected. Next scan will cover setup-cli/.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup-cli/. Files inspected: action.yml, install.sh, install.ps1. All code is consistent with expected setup/install action behavior — downloads gh-aw binary from github.com/github/gh-aw releases, validates SHA256 checksums, installs to /.local/share/gh/extensions/gh-aw. No suspicious network calls, exfiltration, obfuscation, persistence, or unrelated payloads detected. Result: clean.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Threat scan complete for focus area setup-cli/. Inspected action.yml, install.sh, and install.ps1. All files implement standard gh-aw CLI installation: download binary from github/gh-aw releases, SHA256 checksum verification, make executable, set GITHUBOUTPUT. No suspicious code detected. State advanced to focusindex=0 (next: setup/).

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete for focus area: setup/. No credible threats found. All code is legitimate GitHub Actions setup/install runtime. Downloads are from github.com releases only. Secret handling files perform redaction and validation (not exfiltration). No hidden files or obfuscated payloads detected. Next focusindex set to 1 (setup-cli/).

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Threat scan complete for focus area setup-cli/. Inspected action.yml, install.sh, install.ps1. All 3 files implement normal install-only behavior: download gh-aw binary from github/gh-aw releases, verify SHA256 checksums, write GITHUBOUTPUT. No exfiltration, no unrelated network calls, no hidden files. Result: clean.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Threat scan complete for setup-cli/ (focusindex 1). Inspected action.yml, install.sh, install.ps1. All files implement standard gh-aw CLI installation: downloading the binary from github/gh-aw GitHub releases with SHA256 checksum verification, installing to /.local/share/gh/extensions/gh-aw, and writing installedversion to GITHUBOUTPUT. No secret collection, exfiltration, obfuscation, or unexpected behavior detected. Result: clean.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete for focus area: setup/ (532 files). No credible threats found. All network calls (OTLP telemetry, api-proxy sidecar reflect, GitHub Actions artifact uploads) fit documented setup/install behavior. Sensitive attribute redaction is in place for telemetry. No hidden files, obfuscated payloads, or exfiltration patterns detected. Next scan will cover setup-cli/.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Threat scan complete for focus area: setup-cli/. Inspected action.yml, install.sh, install.ps1. All files are clean — standard gh-aw CLI installer that downloads binaries from github/gh-aw releases with SHA256 checksum verification. No suspicious behavior detected. Next scan will cover setup/.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup-cli/. Inspected action.yml, install.sh, install.ps1. All files consistent with expected install/setup behavior — downloads gh-aw binary from GitHub releases with SHA256 checksum verification. No exfiltration, obfuscation, or suspicious behavior found. Result: clean. Next round-robin focus: setup/.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Verdict: clean. The setup action performs only its stated purpose — copying runtime files and sending opt-in OTLP telemetry — with no secret exfiltration, obfuscated code, dynamic execution, or unauthorized network access detected.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup/. Scanned all shell scripts, JS/CJS files, action metadata, and checked for suspicious patterns (exfiltration, obfuscation, mining, hidden files). All findings are clean: curl downloads are from github.com release URLs with checksum verification, crypto usage is for ID generation only, base64 is for standard GitHub API/git auth usage, OTLP telemetry is opt-in. No credible threats found. Next scan will focus on setup-cli/.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Threat scan of setup-cli/ complete — no threats found. Files inspected: action.yml, install.sh, install.ps1. All network calls are to github.com/github/gh-aw releases and api.github.com for version resolution. GHTOKEN used only for GitHub API auth. SHA256 checksum verification present. Next round-robin focus: setup/.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete for focus area setup-cli/. Scanned action.yml, install.sh, and install.ps1. All files implement standard binary download/install behavior (detect OS/arch, gh extension install with fallback, SHA256 checksum verification from github.com/github/gh-aw releases). No threats found. Next scan will cover setup/.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Threat scan complete — focus area: setup-cli/. All 3 independent judges returned clean. Files (action.yml, install.sh, install.ps1) show only expected installer behavior: downloads from github.com/github/gh-aw releases, GHTOKEN used exclusively for GitHub API auth, SHA256 checksum verification on by default, no exfiltration or obfuscation detected. Next focus area: setup/ (index 0).

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup/. Result: CLEAN. All 3 LLM judges agreed — no obfuscation, no exfiltration, no suspicious outbound URLs, no hidden files. OTLP telemetry is user-configured only. 500 CJS files implement expected GitHub Actions workflow helpers. One .bak test backup found (non-runtime, benign). Next scan will cover setup-cli/.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup-cli/. Scanned action.yml, install.sh, install.ps1. All files are consistent with a standard CLI installer: downloading gh-aw binary from GitHub releases with SHA256 checksum verification, no secret exfiltration, no unrelated network calls, no obfuscated payloads. Result: clean. Next scan will cover setup/.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Verdict: clean All behaviors are consistent with a legitimate agentic workflow setup action: binary downloads use checksum verification, OTLP telemetry is opt-in via user-configured endpoints (no default), secret validation makes legitimate API calls only to well-known providers using user-supplied keys, and no obfuscation or hardcoded exfiltration endpoints were found. The "antigravity CLI" download from Google Cloud Storage with SHA256 verification follows standard secure distribution practices. Nothing in the findings constitutes a credible security threat beyond normal setup-action behavior.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup/ (529 files). No credible threats found. All network calls are localhost health checks or downloads from github.com/googleapis.com with SHA256 verification. Next run will scan setup-cli/.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Threat scan complete for focus area setup-cli/. Inspected action.yml, install.sh, and installtest.sh. All files are consistent with a setup/install action: binary download from github.com/releases with SHA256 checksum verification, gh extension install attempt, and GitHub Actions output writing. No suspicious behavior detected. Next scan will focus on setup/.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete for focus area setup/. No credible threats found. All 549 files inspected for exfiltration, obfuscation, crypto mining, and unexpected behavior. Network calls are limited to GitHub API and user-configured OTLP endpoints. Base64 usage is standard (GitHub API decoding, git auth headers). Next scan will cover setup-cli/.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Threat scan complete — focus area: setup-cli/. Inspected action.yml, install.sh, installtest.sh. Two independent judges both returned clean. No suspicious code found. State advanced to focusindex=0 (setup/) for next run.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete — focus area: setup/ (focusindex 0). All 3 independent LLM judges (claude-sonnet-4.6, claude-haiku-3-5, gpt-4.1) returned clean. No threats found: no exfiltration, no crypto mining, no obfuscation, no unauthorized network endpoints. OTLP telemetry is user-configured and no-op by default; awfreflect.cjs targets an internal Docker sidecar address. Next scan will cover setup-cli/ (focusindex 1).

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Security audit complete for setup/ action in github/gh-aw-actions. Verdict: clean. All findings examined directly — no threats identified. Files reviewed: action.yml, index.js, post.js, setup.sh, clean.sh, actionsetupotlp.cjs, sendotlpspan.cjs, installawfbinary.sh, installthreatdetectbinary.sh. Scanned for obfuscation, exfiltration, tunneling, crypto mining, suspicious base64 usage, and hardcoded malicious URLs. All clear.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Threat scan verdict: CLEAN. Analysis complete — no credible threats found in setup/ action directory. All indicators reviewed: network calls, telemetry, binary installers, JS files, shell scripts, and .bak file.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Security review complete. Verdict: clean. All network traffic is limited to github.com and api.github.com for the github/gh-aw repo. SHA256 checksum validation is present. GHTOKEN is only passed as an env var for the gh CLI (standard practice). Install target is the canonical gh extensions directory. No obfuscation, no external URLs, no telemetry, no exfiltration patterns detected across all three files.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Security analysis complete for setup-cli action in github/gh-aw-actions. Verdict: clean. All reviewed criteria indicate standard, safe CLI install behavior with no indicators of compromise.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Security analysis complete. Verdict: CLEAN. All curl calls target github.com or api.github.com only (hardcoded REPO="github/gh-aw"). GHTOKEN is passed solely as an env var for the gh CLI — never echoed, logged, or embedded in any curl header/URL. No eval, base64, obfuscated blobs, or external domains found. Installation is user-space only ($HOME/.local/share/gh/extensions/), with SHA256 checksum verification by default. The script is consistent with a standard, production-quality GitHub Actions CLI setup action.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Verdict: CLEAN The setup/ action is consistent with a legitimate GitHub Actions setup/install action. All observed behaviors are expected: File operations: Copies bundled .cjs/.sh/.json files to $RUNNERTEMP/gh-aw/actions — standard pattern for setup actions. Network activity: Limited to user-configured OTLP endpoints, localhost health checks, official GitHub release downloads (with SHA256 verification), and the official GitHub CLI source. No hardcoded suspicious endpoints. Token handling: Tokens are passed only to Docker containers and git operations — no exfiltration to third-party services. Cleanup: post.js removes only /tmp/gh-aw/ and chroot directories create...

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup/ (focusindex=0). Scanned 539 files including action.yml, index.js, post.js, setup.sh, clean.sh, 400+ .cjs scripts, and shell scripts. All 3 independent LLM judges returned clean. Findings: OTLP telemetry is user-configured and optional; binary downloads use SHA256 verification from github.com and storage.googleapis.com; no token exfiltration, obfuscation, mining, or persistence found; one inert .bak test artifact (handlenoopmessage.test.cjs.bak) is not executed at runtime. Next scan will focus on setup-cli/. Audit trail written to cache-memory.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete — focus area: setup-cli/ (focusindex 1). Scanned 3 files: action.yml, install.sh, installtest.sh. No hidden files found. Three independent judges (2× sonnet, 1× haiku) all returned clean. Network calls are strictly scoped to github.com and api.github.com for binary download/checksum. GHTOKEN is only passed to the gh CLI via standard env convention and never sent to third-party endpoints. No obfuscation, eval, persistence, or exfiltration patterns detected. Next run will scan setup/ (focusindex 0).

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete — focus area: setup/. All 3 independent judges (2× sonnet, 1× haiku) returned clean. No exfiltration, obfuscation, mining, or malicious behavior found. Binary installs use SHA256 verification from github.com releases. OTLP telemetry is opt-in and fully user-configured (no hardcoded endpoints). Secret validation calls only official APIs. No issue filed. State advanced to focusindex=1 (next run: setup-cli/).

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup/. No threats found. 3/3 independent judges returned clean verdicts. Inspected 15 key files including entry points (index.js, post.js, setup.sh), OTLP telemetry code, secret redaction logic, install scripts, and hidden files. All behaviors are consistent with legitimate CI/CD setup action: file copy operations, opt-in telemetry, checksum-verified binary installs from official GitHub/GCS sources. Next scan will cover setup-cli/. State updated to focusindex=1.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Threat scan complete — focus area: setup-cli/. Scanned 3 files (action.yml, install.sh, installtest.sh). All 3 independent judge agents (sonnet, haiku, deep-static) returned verdict clean. No secret exfiltration, no unexpected outbound calls, no obfuscation, no persistence, no privilege escalation found. Cache state updated; next run will scan setup/.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete — focus area: setup-cli/. Scanned 3 files (action.yml, install.sh, installtest.sh). No hidden files. All three independent judge sub-agents (sonnet, haiku, opus) returned clean. Network egress is exclusively to github.com/api.github.com for official release downloads; GHTOKEN is consumed only by the gh CLI; SHA256 checksum verification is on by default; no obfuscation, no exfiltration, no unexpected persistence. Next scan will focus on setup/.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Round-robin scan complete. Focus area: setup/. Result: CLEAN. Deep inspection found no credible threats — no exfiltration, no obfuscated payloads, no anomalous network calls. One noted hygiene gap: installantigravitycli.sh skips SHA256 checksum verification when checksums.txt returns HTTP 404 (documented design choice, consistent with supporting pre-release versions). All 3 independent LLM judges (sonnet-4-5, haiku-4-5, haiku-4-5) agreed this is not a supply-chain threat. State advanced to focusindex=1 (setup-cli/ next).

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Security review complete — verdict: clean. Reviewed setup/ directory of github/gh-aw-actions. All network access is scoped and purposeful, no secret exfiltration, no obfuscation, no unauthorized endpoints. No issue created.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Security review complete for setup-cli/. Verdict: CLEAN. All 3 files reviewed against actual source. No threats found. Details in response.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Security verdict: clean. Rationale: All behaviors align with legitimate setup action functionality. OTLP telemetry is user-opt-in and token/secret payloads are sanitized before transmission. The (apiproxy/redacted) call targets a localhost Docker sidecar — internal runtime communication expected for a firewall/proxy architecture, not exfiltration. Binary installations from GitHub and GCS use SHA256 checksum verification, which is best-practice supply chain hygiene. The .bak file is a test artifact not deployed to the action runtime and poses no execution risk. No eval/dynamic code execution, obfuscation, or cryptocurrency indicators were found.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Security threat assessment complete — verdict: CLEAN. Verdict: clean Rationale: All observed network activity, file operations, and credential handling are consistent with the repository's stated purpose as a GitHub Actions setup action for agentic AI workflows. Every external network call is either: (a) downloading pinned binaries from GitHub/Google with SHA256 checksum verification, (b) sending observability telemetry to caller-configured OTLP endpoints, (c) validating API credentials against their respective official providers, or (d) using standard GitHub Actions token patterns (ACTIONSRUNTIMETOKEN). There is no obfuscation, no dynamic code construction via e...

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete — focus area: setup/. All 3 independent judges returned clean. Scanned: action.yml, index.js, post.js, setup.sh, clean.sh, setup/sh/ (9 key scripts), setup/js/ (key CJS files including OTLP, safe-outputs, auth, secrets). No credential exfiltration, obfuscation, unexpected payloads, or persistence mechanisms found. All downloads use github.com releases with SHA256 verification. OTLP telemetry is operator-configured only. Next run will scan setup-cli/.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Security analysis complete. Verdict: clean. No indicators of compromise found in the setup/ directory based on the provided evidence summary.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Security review complete. Overall verdict: CLEAN. No genuine threats found in setup-cli/ (action.yml + install.sh + installtest.sh).

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Daily runtime threat scan complete for focus area: setup/. All 3 independent sub-agent judges (2x Haiku explore, 1x Sonnet general-purpose) unanimously returned clean. Scanned 525 files including action.yml, setup.sh, post.js, index.js, validatesecrets.cjs, sendotlpspan.cjs, installantigravitycli.sh, and all shell/JS sources. No exfiltration, obfuscation, crypto-mining, eval() abuse, or suspicious network targets found. Binary installs use SHA256 verification; OTLP telemetry is user-configured only; secret validation calls official provider APIs only. Next scan focus: setup-cli/ (focusindex=1). Run note saved to cache-memory.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Threat analysis complete. Verdict: CLEAN. All network calls are scoped to github.com/api.github.com for legitimate release download/version resolution. GHTOKEN is in the environment for gh CLI use only and is never appended to any curl call. SHA256 checksum validation is implemented. No obfuscated blobs, no third-party exfiltration endpoints, no privilege escalation, no eval of downloaded content.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete — focus area: setup-cli/. Scanned 3 files (action.yml, install.sh, installtest.sh), no hidden files. All 3 independent LLM judges returned clean. All network calls confined to github.com and api.github.com for github/gh-aw releases only; GHTOKEN passed to gh CLI subprocess (standard practice), never exfiltrated; SHA256 checksum verification on by default; no obfuscation, eval, base64 blobs, persistence, privilege escalation, or third-party domains detected. Next scan will focus on setup/.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup/ (focusindex 0 → 1). All 3 independent judge sub-agents returned clean verdict. 522 files inspected; no threats found. Key observations: (1) installantigravitycli.sh downloads from GCS with SHA256 verification — legitimate installer pattern; (2) @earendil-works/pi- npm packages are runtime dependencies not pinned in package.json — supply chain gap noted but not malicious; (3) OTLP telemetry is user-configured no-op with active secret redaction; (4) zero eval() calls, no hidden files, no persistence mechanisms, no exfiltration to unexpected domains. Next scan will cover setup-cli/.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Security analysis complete: clean. All network calls accounted for. No eval/exec with user-controlled strings. No exfiltration patterns. No unexpected destinations.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete — focus area: setup-cli/. All 3 independent judges returned clean. Files scanned: action.yml, install.sh, installtest.sh. All network calls are scoped to github.com/api.github.com only; REPO is hardcoded; GHTOKEN is used only by the gh CLI; SHA256 checksum verification is enforced by default. No hidden files, binary blobs, obfuscated code, exfiltration, or persistence mechanisms found. One functional bug noted (output key mismatch installed-version vs installedversion) but not a security issue. State updated: next scan will cover setup/ (focusindex=0).

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup-cli/ (focusindex 1). Scanned 3 files: action.yml, install.sh, installtest.sh. All network calls are scoped exclusively to github.com/github/gh-aw and api.github.com (hardcoded REPO). SHA256 checksum verification is present. GHTOKEN is used only for gh CLI authentication — never exfiltrated. No eval, base64 decode, obfuscated code, hidden files, or suspicious patterns found. 3/3 independent judge verdicts: clean. Next scan will cover setup/ (focusindex 0).

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete — focus area: setup/. Scanned 516 files (516 JS .cjs, shell scripts, action metadata). All 3 LLM judges returned clean unanimously. No suspicious behavior found: all binary downloads target github.com/storage.googleapis.com with SHA256 verification; API key handling scoped to local Docker proxy only; OTLP telemetry sanitizes sensitive fields before export; no eval/obfuscation/crypto-mining/persistence. Minor stale artifact (handlenoopmessage.test.cjs.bak) has no runtime impact. State advanced to focusindex=1 (setup-cli/) for the next run.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Verdict: CLEAN Rationale: All network calls target known-legitimate endpoints (github.com, storage.googleapis.com, api.anthropic.com, api.openai.com, api.notion.com), binary installs use SHA256 checksum verification, and no obfuscation, exfiltration, or attacker-controlled infrastructure was identified. The validatesecrets.cjs behavior — reading multiple API keys and probing their respective APIs — is consistent with credential pre-flight validation in an agentic workflow setup; only HTTP status codes are reported, not the secrets themselves. One minor hygiene concern: installantigravitycli.sh silently skips checksum verification when checksums.txt returns 404, c...

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete — focus area: setup-cli/. Scanned 3 files (action.yml, install.sh, installtest.sh). All 3 independent LLM judges returned verdict: clean. Network calls exclusively target github.com and api.github.com for binary download/checksum. SHA256 verification enabled by default. GHTOKEN not forwarded externally. No obfuscation, persistence, or exfiltration detected. No hidden files found. Next focus area: setup/.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup-cli/. Scanned 3 files (action.yml, install.sh, installtest.sh). All 3 LLM judges returned CLEAN (high confidence). No suspicious code found — all network calls go to github.com/api.github.com, SHA256 checksum verification is enabled by default, no token exfiltration, no obfuscation, no privilege escalation. Next round-robin focus: setup/. Audit trail written to cache-memory.

complete live noop

[aw] Daily Runtime Threat Scan failed

Workflow Failure Workflow: Daily Runtime Threat Scan Branch: sync/gh-aw-v0.80.2 Run: https://github.com/github/gh-aw-actions/actions/runs/27663652954 [!WARNING] Invalid or Unsupported Model: The agent failed because the configured model name is invalid, unknown, or unavailable for this engine/account. This is a configuration issue, not a transient error — retrying will not help. <details> <summary>How to fix this</summary> Specify a valid model for the selected engine in the workflow frontmatter: To find valid models, check your engine/provider documentation (for Copilot see supported models). </details> [!WARNING] Engine Failure: The copilot engine terminated unexpectedly. Last agent out...

closed live issue

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Daily runtime threat scan complete. Focus area: setup/ (round-robin index 0). Scanned 370+ JavaScript files, 60+ shell scripts, action metadata, and install scripts. Three independent LLM judges unanimously returned clean. No secret collection, exfiltration, obfuscated code, crypto mining, or unauthorized network calls found. All binary installs use HTTPS + SHA256 checksum verification from official sources (github.com releases or documented GCS bucket for the Antigravity AI engine). State advanced to focusindex=1 (setup-cli/) for the next run.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Scan complete — focus area: setup-cli/. Files scanned: action.yml, install.sh, installtest.sh. No hidden files found. All 3 independent judges returned clean (3/3 consensus). The install script only makes network calls to github.com and api.github.com to download the gh-aw binary with SHA256 verification. GHTOKEN is passed only as an ambient env var for the gh CLI and is never read or transmitted by the script. No obfuscation, eval, exfiltration, persistence, or privilege escalation detected. Next round-robin focusindex advanced to 0 (setup/).

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup/ (focusindex=0, next=1 for setup-cli/). Scanned 509 files across setup/js/.cjs, setup/sh/.sh, setup/action.yml, setup/index.js, setup/post.js, setup/setup.sh, setup/clean.sh. No credible threats found. All network calls target legitimate destinations (api.github.com, GitHub releases, user-configured OTLP endpoints, internal Docker api-proxy). installantigravitycli.sh downloads the GitHub-internal Antigravity AI CLI from GCS with SHA256 verification — confirmed as a recognized AI engine in the repo's own awf-config. No obfuscation, exfiltration, or persistence patterns detected. Three independent LLM judges all retur...

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Verdict: CLEAN. Security scan complete — no threat detected in setup/ directory. All install scripts use SHA256 verification, telemetry only fires to user-configured endpoints (no hardcoded exfiltration), credential handling follows standard Octokit patterns without external calls, and the post step explicitly removes /tmp/gh-aw/ rather than persisting anything. The one minor note (antigravity checksum skip on 404) is a defensive-optional pattern for a non-critical install, not a threat signal.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Threat scan complete. Verdict: CLEAN Findings Summary 1. Binary files — CLEAN No unexpected binary files found. All files in setup/ are text (JS, shell, JSON). 2. Suspicious URLs — CLEAN (with notes) (apiproxy/redacted) — internal runner-local proxy service; expected in this architecture (docs.anthropic.com/redacted), (platform.openai.com/redacted), (brave.com/redacted), (developers.notion.com/redacted) — documentation reference strings inside validatesecrets.cjs error messages; not fetched at runtime (labs.boostsecurity.io/redacted) — appears only in code comments, not executed (storage.googleapis.com/redacted) — third-party GCS bucket used by installantigravity...

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Security analysis complete for setup-cli/. Verdict: CLEAN. All 3 files reviewed (action.yml, install.sh, installtest.sh). No threats found.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Security scan complete — verdict: CLEAN. No threats found in setup/ directory. All network calls, credential handling, binary downloads, and code patterns are appropriate and well-explained.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup/. All 3 independent judges (2x claude-sonnet-4.6, 1x claude-haiku-4-5) returned clean verdicts. No credible threats found. Minor hygiene note: installantigravitycli.sh skips SHA256 verification when checksums.txt returns HTTP 404 (self-documented, non-malicious). State updated: next scan will cover setup-cli/ (focusindex=1). Run note saved to cache-memory.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Security analysis complete. Verdict: clean. All three files in setup-cli/ exhibit standard, secure GitHub Actions patterns with no indicators of malicious behavior.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete — focus area: setup-cli/. All 3 independent judges (sonnet, haiku, code-review) returned unanimous clean verdict. Files inspected: action.yml, install.sh, installtest.sh. All network calls scoped exclusively to github.com/github/gh-aw and api.github.com. GHTOKEN used only internally by gh CLI. SHA256 checksum verification enabled by default. No secret exfiltration, obfuscation, unauthorized endpoints, or privilege escalation detected. Next focus area: setup/ (focusindex reset to 0).

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Security analysis complete. Verdict: CLEAN. All curl usage in shell scripts is for binary downloads with SHA256 checksum verification — no POST of secrets. No eval(), no base64-decoded execution, no dynamic require(), no hardcoded exfiltration endpoints found in .cjs or .sh files.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Security threat assessment complete for github/gh-aw-actions setup/ directory. Verdict: CLEAN. All findings have legitimate explanations — base64 for GitHub API decoding, opt-in telemetry with no credential leakage, checksum-verified installers, and local-only secret validation reports. No malicious patterns detected.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Security assessment complete on setup-cli/ in github/gh-aw-actions. Verdict: clean. No threats detected — all behaviors are consistent with a legitimate setup/install action.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Security analysis complete. Verdict: clean. All behaviors observed in action.yml and install.sh are consistent with a standard CLI installation action for the gh-aw GitHub CLI extension.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete — focus area: setup/. Inspected 170+ files including action.yml, index.js, post.js, setup.sh, clean.sh, and a representative sample of JS and shell scripts. Three independent LLM judges unanimously returned clean. All network egress is accounted for (opt-in OTLP telemetry, SHA256-verified binary downloads from github.com/GCS, token validation against official vendor APIs only). No eval/obfuscation, no hidden files, no exfiltration patterns, no crypto mining. Next scan will cover setup-cli/ (focusindex=1).

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Threat scan complete for focus area setup/ — result: clean. All 3 independent LLM judges returned clean verdicts. Inspected action.yml, index.js, post.js, setup.sh, clean.sh, 20+ JavaScript files, and all shell scripts. No exfiltration, obfuscation, crypto mining, or unexpected network targets found. Network calls are exclusively to: official GitHub/npm APIs, user-configured OTLP endpoints, localhost (MCP health checks), and known tool download sources (cli.github.com, GitHub releases, GCS bucket for Antigravity CLI). Round-robin advanced to focusindex: 1 (setup-cli/ for next run). Run note written to cache-memory.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Security audit complete. Verdict: clean. Evidence reviewed: setup.sh copy logic, validatesecrets.cjs (full), dynamiccheckout.cjs, handlenoopmessage.test.cjs.bak, otlp.cjs, sendotlpspan.cjs, action.yml.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Security analysis complete. Verdict: clean. All network destinations are legitimate (github.com, googleapis.com), credentials are used only for standard GitHub operations, OTLP telemetry is caller-configured and excludes secrets, base64 usage follows standard patterns, and no obfuscation/eval/malicious payload indicators were found.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete — focus area: setup/ (479 files). Three LLM judges evaluated all findings. No finding reached the 2-judge consensus threshold for escalation. Notable observations (below threshold): (1) installantigravitycli.sh downloads Antigravity CLI from GCS with same-origin checksums — 1/3 judges flagged as medium risk; (2) OTLP OIDC bearer token written to GITHUBENV — 1/3 judges flagged as low risk. Both are hardening gaps, not active threats. All other files (validatesecrets.cjs, sendotlpspan.cjs, setup.sh, install scripts) assessed clean by all judges. Next round-robin focus: setup-cli/.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Scan complete for focus area: setup/. No credible threats found. All outbound network calls are to github.com releases for binary installs or localhost health checks. OTLP telemetry is user-configured and sanitizes sensitive keys. Credential scripts remove credentials (security measure). No obfuscated blobs, hidden files, crypto miners, or exfiltration patterns detected. State updated; next scan will cover setup-cli/.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete — focus area: setup/ (479 files). No credible threats found. All network calls use user-configured OTLP endpoints or official APIs (GitHub, Anthropic, OpenAI). Secret validation in validatesecrets.cjs tests credentials only against their legitimate APIs. No hidden files, binaries, obfuscated blobs, or exfiltration targets detected. 3/3 LLM judges (claude-sonnet, gpt-4.1, gemini-2.5-pro) returned clean. Next scan will cover setup-cli/.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete for focus area setup-cli/. Inspected 3 files: action.yml, install.sh, installtest.sh. All files are consistent with expected CLI install behavior: binary download from github/gh-aw releases with SHA256 checksum validation, standard GitHub Actions token scoping, no secret exfiltration or obfuscated code. Result: clean. Next run will scan setup/.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup-cli/. Inspected: action.yml, install.sh, installtest.sh. All files are consistent with a legitimate CLI install action (downloads gh-aw binary from github.com/github/gh-aw releases, SHA256 checksum verification, no secret exfiltration or suspicious behavior). Result: clean.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Verdict: clean. The setup action follows standard GitHub Actions patterns: file copying to RUNNERTEMP, tool installation with SHA256 checksum verification, network calls limited to GitHub releases and GCS (expected for binary downloads), and no credential exfiltration, obfuscation, or unexpected telemetry. The .bak file is a minor artifact (backed-up test file) with no security impact.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup-cli/. Inspected 3 files (action.yml, install.sh, installtest.sh). All behavior is consistent with a legitimate CLI install action — downloads gh-aw binary from github/gh-aw releases with SHA256 checksum verification, no exfiltration, obfuscation, or suspicious patterns detected. Result: clean.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete for focus area: setup/. Scanned all shell scripts, JavaScript/CJS files, action.yml, and checked for hidden files. No credible threats found. Network calls are limited to GitHub releases (with SHA256 verification) and configurable OTLP endpoints. No secret exfiltration, obfuscation, mining, persistence, or unrelated payloads detected. Round-robin state advanced to focusindex=1 (setup-cli/) for the next run.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Scan complete for focus area setup-cli/. Inspected action.yml, install.sh, and installtest.sh. All code is consistent with expected setup/install behavior: downloads gh-aw binary from official GitHub releases, verifies SHA256 checksums, uses gh extension install with version pinning. No exfiltration, obfuscation, persistence, or suspicious patterns found. Result: clean. Next focus area: setup/ (index 0).

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Scan complete — focus area: setup-cli/. Inspected action.yml, install.sh, installtest.sh. No threats found. install.sh performs a standard binary install from github.com/github/gh-aw releases with SHA256 checksum verification and a gh extension install fallback. No secret exfiltration, obfuscation, or unrelated network calls detected.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Scan complete for setup-cli/ (focusindex 1). Files inspected: action.yml, install.sh, installtest.sh. All code is consistent with a standard CLI installer: downloads gh-aw binary from github/gh-aw GitHub releases, performs SHA256 checksum verification, uses gh extension install with fallback to direct download, writes only to $HOME/.local/share/gh/extensions/gh-aw and GITHUBOUTPUT. No threats found.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup/. All files inspected (action.yml, setup.sh, clean.sh, index.js, post.js, js/.cjs, sh/.sh, md/.md). No credible threats found — network calls are legitimate binary downloads from github.com with SHA256 verification, OTLP telemetry is documented behavior, no secret exfiltration patterns, no hidden files or obfuscated blobs.

complete live noop

Daily Runtime Threat Scan completed with no action

Daily Runtime Threat Scan Threat scan complete — focus area: setup-cli/. All 3 files (action.yml, install.sh, installtest.sh) inspected. install.sh downloads the gh-aw binary from github.com/github/gh-aw releases with SHA256 checksum validation; all curl calls target expected release URLs. No exfiltration, obfuscated code, hidden files, or suspicious behavior found. Result: clean.

complete live noop

Comment on safe output

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup/. No credible threats found. All network calls in install scripts target legitimate destinations (github.com releases, storage.googleapis.com for antigravity CLI, cli.github.com apt repo). GHTOKEN usage is limited to git clone authentication and DIFC proxy container configuration — both expected for a setup/install action. No base64/eval obfuscation, no token exfiltration, no unrelated payloads detected. One benign .bak test file found. State updated; next run will scan setup-cli/.

published live comment

Comment on safe output

Daily Runtime Threat Scan Scan complete for focus area: setup/. Inspected 459 files (JS, CJS, shell scripts, YAML). No credible threats found. Network calls are legitimate (GitHub CLI keyring, GitHub releases, GCS public bucket for antigravity CLI, GitHub/Anthropic APIs for secret validation). No obfuscated code, hidden files, crypto mining, or exfiltration patterns detected. State updated: next scan will target setup-cli/.

published live comment

Comment on safe output

Daily Runtime Threat Scan Scan complete for focus area setup-cli/. Inspected 3 files: action.yml, install.sh, installtest.sh. All code is consistent with expected setup/install behavior — downloads gh-aw binary from github.com/github/gh-aw releases with SHA256 checksum verification. No exfiltration, obfuscation, persistence, or unrelated network calls found. Result: clean.

published live comment

Comment on safe output

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup/. Scanned action.yml, index.js, setup.sh, post.js, all .cjs files (js/) and .sh files (sh/). No threats found. All curl/network usage is for binary downloads from github.com and local MCP health-checks. Crypto module usage is for SHA256 hashing/random bytes. Token handling is validation-only. Result: clean. Next round-robin focus: setup-cli/.

published live comment

Comment on safe output

Daily Runtime Threat Scan Threat scan complete for focus area setup/. No credible threats found. All curl calls are for installing official binaries; OTLP spans are user-configured telemetry; base64 usage is for GitHub API file decoding and git auth headers. One .bak test file found (benign). State updated: next scan will cover setup-cli/.

published live comment

Comment on safe output

Daily Runtime Threat Scan Threat scan complete for focus area setup-cli/. Inspected action.yml, install.sh, and installtest.sh. All files exhibit expected setup/install behavior: binary download from github.com/github/gh-aw releases with SHA256 checksum verification and gh extension install fallback. No suspicious patterns found (no obfuscation, exfiltration, encoded blobs, or unrelated network calls). Result: clean. Next round-robin focus: setup/.

published live comment

Comment on safe output

Daily Runtime Threat Scan Threat scan complete — focus area: setup-cli/ — result: clean. Inspected action.yml, install.sh, installtest.sh. All behavior is consistent with a legitimate CLI install action (downloads gh-aw binary from GitHub releases with SHA256 checksum verification, no exfiltration or unrelated network calls). Next scan will cover setup/.

published live comment

Comment on safe output

Daily Runtime Threat Scan Security analysis complete. Verdict: clean. The action and install script are legitimate installation tooling with no suspicious behavior detected.

published live comment

Comment on safe output

Daily Runtime Threat Scan Security analysis complete. Verdict: clean.

published live comment

Comment on safe output

Daily Runtime Threat Scan Security analysis complete. Verdict: clean

published live comment

Comment on safe output

Daily Runtime Threat Scan Threat scan complete — focus area: setup/. No credible threats found. Scanned all shell scripts, JavaScript/CJS files, and action metadata. Outbound network calls are limited to github.com releases (binary installs), localhost (MCP gateway health), and official AI provider APIs (anthropic, openai, brave, notion) for key validation only. No obfuscation, exfiltration, persistence, or unrelated payloads detected. Next scan will cover setup-cli/.

published live comment

Comment on safe output

Daily Runtime Threat Scan Scan complete for focus area setup-cli/. Inspected action.yml, install.sh, and installtest.sh. All files are consistent with a standard CLI install action: binary downloaded from github/gh-aw releases with SHA256 checksum verification, GHTOKEN used only for gh CLI auth, no exfiltration or obfuscation detected. Result: clean.

published live comment

Comment on safe output

Daily Runtime Threat Scan Runtime threat scan complete for focus area setup-cli/. Inspected 3 files: action.yml, install.sh, installtest.sh. All behavior is consistent with expected setup/install action purpose — binary download from official GitHub releases (github/gh-aw) with SHA256 checksum verification, version pinning, and gh extension install fallback. No suspicious code found: no exfiltration, no obfuscation, no unrelated payloads, no persistence attempts. Result: clean.

published live comment

Comment on safe output

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup/. Result: clean. No suspicious code found — all network calls, secret access, and shell scripts are consistent with legitimate setup/install action behavior for the gh-aw project. Next run will scan setup-cli/.

published live comment

Comment on safe output

Daily Runtime Threat Scan Security review complete: verdict is clean. No threats detected in setup/ directory evidence.

published live comment

Comment on safe output

Daily Runtime Threat Scan Runtime threat scan complete. Focus area: setup/. Scanned action.yml, setup.sh, index.js, post.js, all shell scripts in sh/, and key JavaScript files in js/. All outbound network calls are legitimate (GitHub releases with SHA256 checksum verification, or localhost health checks). No credential exfiltration, obfuscated blobs, crypto mining, persistence mechanisms, or suspicious behavior detected. The single .bak file found (handlenoopmessage.test.cjs.bak) is a benign test file backup. Result: clean.

published live comment

Comment on safe output

Daily Runtime Threat Scan Threat scan complete for focus area: setup/. No credible threats found. All code is consistent with legitimate setup/install action behavior: tool installation with checksum verification, MCP gateway management, local health checks, authenticated git operations, and secret validation against their respective APIs. State advanced to next focus area (setup-cli/) for next run.

published live comment

Comment on safe output

Daily Runtime Threat Scan Security review complete for setup-cli/. Verdict: clean. No threats detected.

published live comment

Comment on safe output

Daily Runtime Threat Scan Runtime threat scan complete — focus area: setup-cli/ (3 files: action.yml, install.sh, installtest.sh). All 3 independent LLM judges returned clean. The action is a standard CLI installer downloading from github.com/github/gh-aw releases with SHA256 checksum verification. No threats found. Next scan will cover setup/.

published live comment

Comment on safe output

Daily Runtime Threat Scan Security review complete - verdict: clean

published live comment

Comment on safe output

Daily Runtime Threat Scan Security scan complete for focus area: setup/. Scanned action.yml, index.js, post.js, setup.sh, all shell scripts in sh/, and key JavaScript files in js/. All network calls are to github.com releases (for binary downloads) or user-configured OTLP telemetry endpoints. No secret exfiltration, obfuscation, hidden executables, or suspicious payloads detected. Result: clean. Next scan will cover setup-cli/.

published live comment