pwn request
A pull_request_target or similar privileged workflow that checks out and runs a pull request's code, handing an outsider the repository's secrets and write token.
The checkout alone is harmless; the next step that builds, tests or installs from the checked-out tree runs the attacker's code. Build fork code on pull_request instead, where it gets no secrets and a read-only token.