GitHub Actions Audit is answering right now. Last checked 10 min ago. Last commit 11 Jun 2026.
GitHub Actions workflow security audit - 21 checks: pinning, permissions, secrets, injection.
Today is the operative word: we check GitHub Actions Audit every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.
Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 10 min ago.
claude mcp add github-actions-audit --transport http https://unbearable-dev--github-actions-audit.apify.actor/mcp
{
"mcpServers": {
"github-actions-audit": {
"url": "https://unbearable-dev--github-actions-audit.apify.actor/mcp"
}
}
}
[mcp_servers.github-actions-audit]
url = "https://unbearable-dev--github-actions-audit.apify.actor/mcp"
{
"mcpServers": {
"github-actions-audit": {
"url": "https://unbearable-dev--github-actions-audit.apify.actor/mcp"
}
}
}
{
"mcpServers": {
"github-actions-audit": {
"url": "https://unbearable-dev--github-actions-audit.apify.actor/mcp"
}
}
}
This endpoint answered with an authorization challenge. The server is running, but it did not say what kind of credentials it expects.
| URL | Transport | State | Latency | Checked |
|---|---|---|---|---|
| https://unbearable-dev--github-actions-audit.apify.actor/mcp | streamable-http | needs auth | 351 ms | 10 min ago |
Local GitHub Actions/CI maintenance check (action pinning, token perms). Not a full security audit.
Workflow timing analysis, configuration audit and billing insight for GitHub Actions.
AI security layer: code scanning, PII detection, prompt injection, secrets, CVEs
Four IaC audits in one call: Compose, Dockerfile, GitHub Actions, Kubernetes. 131 checks.
Connect AI assistants to GitHub - manage repos, issues, PRs, workflows, and git operations.
MCP server connecting Claude Code to GitHub for an issue to branch to PR to close workflow.
Security scan for AI-generated code: injection, SSRF, secrets, weak crypto, unsafe deserialization.
Security audit for AI agents — scan code/diffs for leaked secrets, check deps via OSV.
Answers built from our own checks of this server.