Agent♥︎Age
Catalog

io.github.eliottreich/taskbounty-check

Official

by eliottreich · JavaScript

Local GitHub Actions/CI maintenance check (action pinning, token perms). Not a full security audit.

taskbounty-check MCP Server

This MCP server implements a local check for GitHub Actions/CI maintenance hygiene, focusing on action pinning, workflow token permissions, and update automation. It inspects GitHub workflow files on the machine to produce a locally written report, and is explicitly not a full security audit.

🛠️ Key Features

  • Checks third-party action pinning
  • Evaluates workflow token permissions
  • Supports update automation
  • Runs on local workflow files (no uploads)
  • Default mode avoids outbound network requests

🚀 Use Cases

  • Reviewing CI maintenance hygiene for GitHub Actions
  • Identifying token-permission issues in workflows
  • Preparing repositories for safer third-party action usage
  • Using opt-in organization checks via --gh-org

⚡ Developer Benefits

  • Local-by-default execution with a locally written report
  • No telemetry and no phone-home behavior
  • Network access only in opt-in --gh-org mode using the user’s gh session
  • Built for apps shipped with Lovable, Bolt, Replit, Cursor, or v0

⚠️ Limitations

  • Not a full security audit
  • Network mode is only available via --gh-org

Topics

ci-cdgithub-actionslocal-firstsecuritysupply-chainvibe-codingci-securityclaude-codecodexcursordevsecopsgithub-actions-securitygithub-securitymcpmcp-serversoftware-supply-chain