github-actions-audit

IntegrationSecurity

Find security weaknesses in your GitHub Actions workflows before they turn into real problems. Once added, your AI can run a 21-check audit covering action pinning, permissions, secrets handling, and injection risks, then explain what it finds.

Serves today. ahel can serve it to every connected agent through your gateway link.

After adding it, ask your AI to audit a GitHub Actions workflow in your project. It will run the checks and flag anything that needs attention.

What your AI can do with it

  • Audit GitHub Actions workflows for security issues
  • Check whether the actions a workflow uses are pinned to specific versions
  • Review workflow permissions for overly broad access
  • Spot problems with how workflows handle secrets
  • Detect injection risks in workflow steps
  • Run all 21 security checks and summarize the findings

ahel review

  • S4info
    community integration — published by unbearabledev, not github

Automated review, not a security audit. Ruleset v1.

Advanced
Delivery
github-actions-audit MCP server → your ahel gateway (mcp.ahel.ai) → every connected AI client.
Catalog kind
mcp-server
Gateway key
io-github-unbearabledev-github-actions-audit
Source
github.com/unbearabledev/github-actions-audit
Hosted endpoint
https://unbearable-dev--github-actions-audit.apify.actor/mcp