Writing GitHub Actions securely is notoriously difficult. As increasingly we're exposing secrets to our GitHub Actions builds, it's worth carefully auditing that those secrets cannot by abused by third parties.