Scan GitHub Actions workflow YAML for pull_request_target misuse, over-permissive tokens, secret leakage, unpinned actions, and unsafe fork checkout patterns.