Audit one GitHub Actions workflow against a contract the caller states. The finding that needs two parts of the file at once: a privileged trigger such as pull_request_target together with a checkout of the contributor ref, which runs untrusted code with the base repository secrets. Also reports an action pinned to a mutable tag, a secret or author-controlled event field interpolated into a run command, an absent permissions block, and the trigger key read as a boolean.
| Network | Scheme | Amount | Pay To |
|---|---|---|---|
| Base | exact | $0.20 USDC | 0x25e8...9608 |