github-actions-audit-mcp
by Tyler FrancisUpdated Aug 12, 2026
Audits GitHub Actions workflow YAML for script injection via untrusted event-context expressions interpolated into shell steps, third-party actions pinned to a mutable tag/branch instead of a commit SHA, missing permissions blocks, and pull_request_target combined with checking out the PR's own head commit.
Audits GitHub Actions workflow YAML for script injection via untrusted event-context expressions interpolated into shell steps, third-party actions pinned to a mutable tag/branch instead of a commit SHA, missing permissions blocks, and pull_request_target combined with checking out the PR's own head commit.