It reads the workflows, runs nothing and never calls the GitHub API. It looks for hidden instructions in a PR title that slip into a shell step, the pull_request_target + fork checkout pattern, third-party actions not pinned to a commit, and secrets written by hand.