The current setup is too complicated and brittle.
Also, it doesn't work for PRs from forked repositories (which is the huge majority of PRs).
Using a fine-grained personal access token and forwarding it to runners via GITHUB_TOKEN should provide an easier setup that works for all PRs.
Solving this issue will also close #82.