script injection
An attack where untrusted text such as an issue title, pasted into a run script through an expression, ends the intended command and runs the attacker's own.
GitHub replaces expressions with their values before the shell starts, so quotes and semicolons in the value become script. Passing the value through an environment variable keeps it as data. actionlint reports untrusted inputs used directly in inline scripts.