- Use environment variables instead of direct interpolation - Prevent shell injection through github context data - Follow GitHub security best practices