IAC Audit Pack is answering right now. Last checked 14 min ago. Last commit 4 Jun 2026.
Four IaC audits in one call: Compose, Dockerfile, GitHub Actions, Kubernetes. 131 checks.
Today is the operative word: we check IAC Audit Pack every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.
Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 14 min ago.
claude mcp add iac-audit-pack --transport http https://unbearable-dev--iac-audit-pack.apify.actor/mcp
{
"mcpServers": {
"iac-audit-pack": {
"url": "https://unbearable-dev--iac-audit-pack.apify.actor/mcp"
}
}
}
[mcp_servers.iac-audit-pack]
url = "https://unbearable-dev--iac-audit-pack.apify.actor/mcp"
{
"mcpServers": {
"iac-audit-pack": {
"url": "https://unbearable-dev--iac-audit-pack.apify.actor/mcp"
}
}
}
{
"mcpServers": {
"iac-audit-pack": {
"url": "https://unbearable-dev--iac-audit-pack.apify.actor/mcp"
}
}
}
This endpoint answered with an authorization challenge. The server is running, but it did not say what kind of credentials it expects.
| URL | Transport | State | Latency | Checked |
|---|---|---|---|---|
| https://unbearable-dev--iac-audit-pack.apify.actor/mcp | streamable-http | needs auth | 375 ms | 14 min ago |
GitHub Actions workflow security audit - 21 checks: pinning, permissions, secrets, injection.
Hadolint-grade Dockerfile audit — 19 checks: secrets, privileges, supply chain, hygiene.
Notes, files, GitHub, and Drive through one MCP connection.
Local GitHub Actions/CI maintenance check (action pinning, token perms). Not a full security audit.
Check whether an npm package, GitHub Action, MCP server or Docker image is dead or abandoned.
Marks every base image in your Dockerfiles, compose files and CI workflows whose security patches ha
kube-linter audit for Kubernetes manifests — 63 checks: security, availability, RBAC, network.
Notes, files, GitHub, and Drive through one MCP connection.
Answers built from our own checks of this server.