github-actions
Build React Native CI Artifacts with GitHub Actions
Mobile teams need repeatable simulator and emulator builds that testers can download. This skill provides reusable GitHub Actions templates and authenticated artifact retrieval examples.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "github-actions" from https://skillstore.io/skills/callstackincubator-github-actions.md and its manifest at https://skillstore.io/api/skills/callstackincubator-github-actions/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "github-actions". Plan simulator and emulator builds for a React Native pull request.
Expected outcome:
- iOS: use a macOS runner, install dependencies, select the shared Xcode scheme, and package the simulator app as a compressed archive.
- Android: use a Linux runner with Java 17, install dependencies, and build the Debug APK through the project Gradle wrapper.
- Artifacts: retain uploads for seven days and publish names, IDs, and authenticated URLs in the workflow summary.
- Security: transfer dynamic inputs through environment variables instead of inserting them directly into Bash source.
Using "github-actions". Explain how QA should retrieve a particular build artifact.
Expected outcome:
- Identify the workflow run and inspect its artifact names, IDs, and expiration status.
- Authenticate with GitHub and download by run ID plus artifact name, or use the REST endpoint with the artifact ID.
- Confirm the selected artifact matches the intended platform and build configuration before testing.
Using "github-actions". Diagnose an Android build that reports an unknown assembledebug task.
Expected outcome:
- The Gradle variant uses incorrect casing.
- Use Debug rather than debug so the generated task matches the project variant.
- Check the module name reported by React Native configuration before retrying.
Security Audit
Medium RiskThree static findings permit command injection through directly interpolated action inputs; the other 75 matches are legitimate build operations or documentation. A separate semantic finding identifies unchecked multiline values that can overwrite workflow outputs and alter downstream settings. No evidence found of malicious intent, credential exfiltration, or prompt injection.
Confirmed security concerns (1)
Capability review items (3)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
โ๏ธ External commands (30)
๐ Filesystem access (10)
๐ Network access (4)
๐ Env variables (2)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/callstackincubator-github-actions/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/callstackincubator-github-actions?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/callstackincubator-github-actions?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/callstackincubator-github-actions/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/callstackincubator-github-actions.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA ยท BibTeX ยท CFF)
APA citation
callstackincubator. (2026). github-actions security audit report (audit version 1) [Author version unspecified]. Skillstore. https://skillstore.io/skills/callstackincubator-github-actions/audits/1BibTeX citation
@techreport{callstackincubator-callstackincubator-github-actions-2026,
author = {callstackincubator},
title = {github-actions security audit report (audit version 1)},
institution = {Skillstore},
year = {2026},
number = {1},
url = {https://skillstore.io/skills/callstackincubator-github-actions/audits/1},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "github-actions security audit report (audit version 1)"
version: "unspecified"
type: report
authors:
- name: "callstackincubator"
date-released: "2026-09-30"
url: "https://skillstore.io/skills/callstackincubator-github-actions/audits/1"
identifiers:
- type: other
value: "skillstore:callstackincubator-github-actions:audit:1"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Create mobile pull request builds
Adapt both composite action templates to produce downloadable iOS simulator apps and Android APKs for pull request validation.
Standardize mobile CI pipelines
Configure runners, dependency installation, build selectors, retention periods, and artifact metadata across both platform jobs.
Retrieve test builds reliably
Use run IDs, artifact names, or artifact IDs to retrieve the correct authenticated build archives for testing.
Try These Prompts
Use github-actions to identify prerequisites for this React Native repository. List required runners, dependencies, the iOS scheme, and the Android variant.
Adapt the Android composite action for this repository using the Debug variant. Expose artifact metadata and pass shell inputs through quoted environment variables.
Create a two-platform workflow using these references. Add pull request and manual triggers, seven-day artifact retention, read-only permissions, and safe shell input handling.
Review this mobile workflow for input injection and artifact selection errors. Propose fixes and authenticated download steps using run IDs and artifact IDs.
Best Practices
- Pass dynamic shell values through environment variables, quote expansions, validate build selectors, and reject line breaks in single-line workflow outputs.
- Use read-only repository permissions and authenticate artifact downloads with appropriately scoped credentials.
- Confirm project schemes and variants, package iOS apps as archives, and retain stable artifact names and IDs.
Avoid
- Insert untrusted action inputs or job outputs directly into Bash source.
- Treat authenticated artifact URLs as public download links or expose tokens in logs.
- Assume default schemes, module names, variants, and runner toolchains match every repository.
Frequently Asked Questions
Which AI tools support this skill?
Does this skill run a hosted build service?
Does it produce store-ready mobile releases?
What runner requirements apply?
How can I download a build artifact?
Can I use the templates unchanged?
Developer Details
Author
callstackincubatorLicense
MIT
Skillstore revision
r1
Version notice
The author did not declare a version.
Ref
7600e968314e2c246773cde1fd359956be68c620
Maintenance freshness
10/1/2026
Usage
0 downloads ยท 0 views
File structure
๐ agents/
๐ openai.yaml
๐ references/
๐ gha-android-composite-action.md
๐ gha-ios-composite-action.md
๐ gha-workflow-and-downloads.md
๐ SKILL.md