3/72 security vendors flagged this file as malicious, includes a big name as Google.
I'd recommend following the security best practices when writing workflows and using GitHub Actions security features to minimize risk of supply chain attacks, which are increasingly popular over the past few years.
Can the VirusTotal report be confirmed as a (false?) positive and worked around?