Nice find. The tokens being leaked in actions log was not one of the security implications I thought of when they released the feature.
How many other actions/libraries do you think are vulnerable?