Detects MCP dependencies in a GitHub repository and generates an OIDC-based GitHub Actions workflow to enforce AgentScore Policy Gate, enabling allow/warn/block decisions on PRs. No API key required.
MIT
GitHub Actions workflow security audit - 21 checks: pinning, permissions, secrets, injection.
GitHub MCP — wraps the GitHub public REST API (no auth required for public endpoints)