github-actions-audit-mcp
by Tyler FrancisUpdated Oct 1, 2026
Audits GitHub Actions workflow YAML for script injection via untrusted event-context expressions interpolated into shell steps, third-party actions pinned to a mutable tag/branch instead of a commit SHA, missing permissions blocks, and pull_request_target combined with checking out the PR's own head commit.
security
github-actions
ci-cd
+4
|How to pay
Subscribe
Monthly billing
$12/month
Predictable monthly cost with included usage. Best for steady, high-volume traffic.
- Unlimited tools within plan limits
- One API key, billed once a month
- Cancel any time
Audit a GitHub Actions workflow for the attacks that actually happen
CI workflows run with your repository's secrets. A few specific mistakes account for most workflow compromises, and this checks for them.
What it catches
- Script injection: untrusted event data (github.event.pull_request.title, branch names, issue bodies) interpolated into shell steps.
- Mutable action refs: third-party actions pinned to a tag or branch instead of a commit SHA.
- Missing permissions blocks, which leave the token over-privileged.
- pull_request_target plus checking out the PR's head commit, the classic pwn-request pattern.
Tools
- audit_workflow: audit a full workflow YAML.
- check_expression_injection: test a single ${{ }} expression for injection risk.
Pricing
Free: 10 audits a day. Pro: unlimited. Static, deterministic checks, no LLM calls, no data stored. Your input is analysed in memory and discarded.