Yes: https://github.com/suzuki-shunsuke/pinact-action
No, you shan't execute random code from internet (that fact that you always execute the same random code is not important)
Github actions is fine in this regards;
Yes: https://github.com/suzuki-shunsuke/pinact-action