Audit one GitHub Actions workflow against a contract the caller states. The finding that needs two parts of the file at once: a privileged trigger such as pull_request_target together with a checkout of the contributor ref, which runs untrusted code with the base repository secrets. Also reports an action pinned to a mutable tag, a secret or author-controlled event field interpolated into a run command, an absent permissions block, and the trigger key read as a boolean.
Coinbase Agentic Market feed · snapshot May 2026 (not live on-chain)
| From | Amount | When |
|---|---|---|
| 0x7e6b65…2b1c | $0.0010 | 2026-09-09T21:47:47 |