Audit a CI workflow for what it leaves movable or undeclared. Reports actions pinned to a tag rather than a commit - a tag can be moved by whoever owns the action, so the code a step runs can change without this file changing - missing permissions and timeouts, a job depending on one that is not declared, a pull_request_target trigger, and an expression interpolated straight into a shell command.
Coinbase Agentic Market feed · snapshot May 2026 (not live on-chain)
| From | Amount | When |
|---|---|---|
| 0x7e6b65…2b1c | $0.0010 | 2026-09-09T21:47:47 |