GitHub Actions exploitation: untrusted input

https://www.synacktiv.com/publications/github-actions-exploitation-untrusted-input.html