GitHub Actions Audit
Verified IntegrationClient Configuration
— Connect GitHub Actions Audit to Claude Desktop or Cursor in seconds{
"mcpServers": {
"github-actions-audit": {
"command": "npx",
"args": [
"-y",
"@modelcontextprotocol/server-github-actions-audit"
],
"env": {}
}
}
}~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows).System Overview
Audits GitHub Actions workflows for supply-chain security risks, detecting script injection, leaked tokens, unpinned actions, and broad permissions.
7/23/2026
Open Source
stdio / SSE RPC
Frequently Asked Questions
Architecture and operational details for GitHub Actions Audit
It detects a comprehensive range of issues such as secret interpolation into run scripts, leaked tokens, unpinned third-party actions, mutable branch references, insecure `GITHUB_TOKEN` permissions, and script injection via untrusted inputs.
Related MCP Servers
Browse all servers →Empower AI assistants to generate and convert documents, manage templates, and automate document workflows efficiently.
Provides a multi-tenant, AI-native Content Delivery Network deployable on Cloudflare, featuring sub-100ms TTFB, AI agent controllability, and comprehensive accessibility.
Deploy a Model Context Protocol server on Cloudflare Workers without requiring authentication.