* Have a conversation about what is in it.
Don't expect a github profile to be professional class code. Sometimes it is just a playground.
So to me it is just one more data source to learn about a candidate.
Start with writing a set of criteria for the role you want to hire and then measure the evidence against that. So for example if you criteria is "writes well commented code" you could use the candidate's code on github for evidence to support that (although a better approach would be to evaluate a work-sample test).
If they are really proud of what they've done, I would want to look at a few sample projects.
If they can explain clearly what their code does, I might even forego a code test. After all, if you aren't paying for the test, you're just wasting their time. There are lots of candidates who won't do an unpaid code test because the subject matter is usually really boring, and they would rather work on something meaningful.
I suppose anything can be faked, so I would be asking myself if their story matches what's on the Github profile. If it doesn't, then what you're seeing is probably fake. If it does, you can use it as a springboard to ask more questions.
Also, if they list a bunch of languages, but they don't have examples in those languages, then have questions about that. (there aren't very many polyglot shops)
Remember, to become a rockstar cpp programmer https://github.com/avinassh/rockstar
Most of the best developers I know either have no GitHub profile or have profiles that are full of noodling that is not indicative of their output.