CI/CD Cordyceps - GitHub Actions Workflow Hijacking and Secret Theft

Monitors GitHub audit logs for suspicious or high-risk activities within CI/CD pipelines, including actions triggered by forks, workflow approvals, branch policy overrides, self-hosted runner registration, and sensitive secret access.