mcpbeat Sign in

GitHub Actions Audit MCP Server

answering

GitHub Actions Audit is answering right now. Last checked 10 min ago. Last commit 11 Jun 2026.

GitHub Actions workflow security audit - 21 checks: pinning, permissions, secrets, injection.

Uptime history 47 days of history
47 days agonow
100.0%
Uptime 24h
91 of 91 checks
Tools
hidden behind auth
422 ms
Response time
average over 24h
0
Stars
last commit 11 Jun 2026

Nothing serious here today

Today is the operative word: we check GitHub Actions Audit every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.

Three servers free · no card

Connect this server

Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 10 min ago.

run in your terminal
claude mcp add github-actions-audit --transport http https://unbearable-dev--github-actions-audit.apify.actor/mcp
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "github-actions-audit": {
      "url": "https://unbearable-dev--github-actions-audit.apify.actor/mcp"
    }
  }
}
~/.codex/config.toml
[mcp_servers.github-actions-audit]
url = "https://unbearable-dev--github-actions-audit.apify.actor/mcp"
.cursor/mcp.json
{
  "mcpServers": {
    "github-actions-audit": {
      "url": "https://unbearable-dev--github-actions-audit.apify.actor/mcp"
    }
  }
}
.vscode/mcp.json
{
  "mcpServers": {
    "github-actions-audit": {
      "url": "https://unbearable-dev--github-actions-audit.apify.actor/mcp"
    }
  }
}

This endpoint answered with an authorization challenge. The server is running, but it did not say what kind of credentials it expects.

Endpoints

URLTransportStateLatencyChecked
https://unbearable-dev--github-actions-audit.apify.actor/mcp streamable-http needs auth 351 ms 10 min ago

Alternatives to GitHub Actions Audit

same job, measured the same way
Taskbounty Check
by eliottreich

Local GitHub Actions/CI maintenance check (action pinning, token perms). Not a full security audit.

65 installs/wk local only
Gha Intel
by barissozudogru

Workflow timing analysis, configuration audit and billing insight for GitHub Actions.

25 installs/wk local only
GuardianShield
by sparkvibe-io

AI security layer: code scanning, PII detection, prompt injection, secrets, CVEs

82 installs/wk local only
IAC Audit Pack
by unbearabledev

Four IaC audits in one call: Compose, Dockerfile, GitHub Actions, Kubernetes. 131 checks.

answering
GitHub
by aifity

Connect AI assistants to GitHub - manage repos, issues, PRs, workflows, and git operations.

local only
okffs
by neturely

MCP server connecting Claude Code to GitHub for an issue to branch to PR to close workflow.

75 installs/wk local only
Code Guard MCP
by mlawsonking

Security scan for AI-generated code: injection, SSRF, secrets, weak crypto, unsafe deserialization.

44 installs/wk local only
MCP Codeaudit
by infoinlet-marketplace

Security audit for AI agents — scan code/diffs for leaked secrets, check deps via OSV.

23 installs/wk local only

GitHub Actions Audit — questions

Answers built from our own checks of this server.

Why is there no tool list for GitHub Actions Audit?
The server answered our handshake with an authorization challenge, so it is running — but it will not describe its tools to an anonymous client. To see them you need to connect with your own credentials. We record it as alive, not as broken: 100.0% of checks in the last 24 hours got a reply.
Is GitHub Actions Audit working right now?
We send a real MCP handshake every 15 minutes. Over the last 24 hours 91 of 91 checks got a reply (100.0%), average response time 422 ms. The bar chart above shows every period we have measured.
How do I connect GitHub Actions Audit?
Copy the ready config from this page — we generate it for Claude Code, Claude Desktop, Codex, Cursor and VS Code, each with the file path that client actually reads. It is a remote server, so there is nothing to install — the client connects to the address. You will need your own credentials: it refuses anonymous clients.
Does GitHub Actions Audit need an API key?
Yes. Every time we knock, GitHub Actions Audit answers with an authorization challenge instead of its tool list — that is how we know it is running and gated rather than broken. Bring your own credentials and it will talk.
How fast is GitHub Actions Audit?
It answers our handshake in 422 ms on average, which is faster than 35% of all working MCP servers we measure. The comparison comes from our own checks across the whole registry, every 15 minutes.
Is GitHub Actions Audit open source?
We cannot say either way: written in Python and 0 stars on GitHub, but we could not determine the licence, and without one the code is not open source by default.