github-actions-audit-mcp

by Tyler FrancisUpdated Aug 12, 2026

Audits GitHub Actions workflow YAML for script injection via untrusted event-context expressions interpolated into shell steps, third-party actions pinned to a mutable tag/branch instead of a commit SHA, missing permissions blocks, and pull_request_target combined with checking out the PR's own head commit.

Audits GitHub Actions workflow YAML for script injection via untrusted event-context expressions interpolated into shell steps, third-party actions pinned to a mutable tag/branch instead of a commit SHA, missing permissions blocks, and pull_request_target combined with checking out the PR's own head commit.