Sviluppo · Server MCP remoto
GitHub Actions Security Audit
Audit GitHub Actions workflows for script injection, unpinned actions and missing permissions.
Cosa indica il MCP Registry
La voce come pubblicata nel MCP Registry ufficiale (consultazione: 4 ottobre 2026), ultima versione.
- Nome nel registro
io.github.tylerscomic-lab/github-actions-audit-mcp- Versione
- 1.0.0
- Stato
- Attivo
- Categoria
- sviluppo
- Trasporto
- Streamable HTTP
- Pubblicato
- 1 ottobre 2026
- Aggiornato
- 1 ottobre 2026
- Editore
- tylerscomic-lab (GitHub) · 25 server con una pagina qui
- Namespace
- Namespace verificato dal MCP Registry tramite GitHub (github.com/tylerscomic-lab) · come funziona
- Elencato in
- Server MCP per GitHub e Server MCP per GitHub Actions
- Repository
- github.com/tylerscomic-lab/github-actions-audit-mcp
- Fonte
- Voce nell’API del registro
Endpoint remoti
| Trasporto | URL | Header dichiarati |
|---|---|---|
| Streamable HTTP | https://github-actions-audit-mcp.mcpize.run/mcp | Nessuno |
Verifica live
Questa directory si è collegata a ogni endpoint remoto e ne ha richiesto l’elenco degli strumenti. La verifica si limita a collegarsi e a elencare gli strumenti; non li esegue, non effettua l’accesso e non testa la sicurezza.
- Raggiungibile
- Sì (HTTP 401)
- Handshake
- Non completato: accesso richiesto
- Accesso richiesto
- Sì - HTTP 401; OAuth annunciato (la risposta rimanda ai suoi metadati di autorizzazione)
- Data della verifica
- 5 ottobre 2026
Come collegare GitHub Actions Security Audit
GitHub Actions Security Audit è un server MCP remoto: non c’è niente da installare. Il suo endpoint, servito tramite Streamable HTTP, è https://github-actions-audit-mcp.mcpize.run/mcp. In un assistente che accetta server MCP remoti (spesso in un’impostazione chiamata connettori, integrazioni o strumenti) si aggiunge un nuovo server indicando questo URL; in un client configurato tramite file lo si aggiunge come server remoto (HTTP) con lo stesso URL.
La voce del registro non dichiara alcun header. Se il server richiede l’accesso, un client che supporta l’autorizzazione MCP apre la pagina di accesso del servizio alla prima connessione.
Ricavato dalla voce del registro; la verifica live riportata sopra mostra solo se l’endpoint ha risposto. Cosa fa il server, e a quali condizioni, lo stabilisce il suo editore; prima di concedergli l’accesso ai propri account o file conviene consultarne il repository o il sito web. Come aggiungere un server MCP a un assistente · Prima di collegare un server
Altri server di tylerscomic-lab (GitHub)
| Server | Esecuzione |
|---|---|
| Claude Cost AuditExact Claude API cost calc with real cache economics, plus a tiktoken-misuse scanner. | Remoto · HTTPVerifica live: accesso richiesto |
| Cron Schedule AuditValidates cron expressions and finds DST bugs that make jobs silently skip or double-fire. | Remoto · HTTPVerifica live: accesso richiesto |
| Dockerfile Security AuditAudit Dockerfiles for root users, baked-in secrets, curl-pipe-shell and unpinned base images. | Remoto · HTTPVerifica live: accesso richiesto |
| Economic Calendar & News RiskFOMC/NFP/CPI economic calendar plus prop-firm news-restriction window checks for futures traders. | Remoto · HTTPVerifica live: accesso richiesto |
| FINRA Broker & Advisor CheckVet US financial advisors and firms from live FINRA BrokerCheck records with ranked red flags. | Remoto · HTTPVerifica live: accesso richiesto |
| Gig Worker Tax Toolkit2026 quarterly tax estimates, SE tax, safe harbor and mileage for 1099 gig workers. | Remoto · HTTPVerifica live: accesso richiesto |
| LedgerIQ 1099 & W-2 Compliance Checker1099/W-2 rules: is a form required, deadlines, backup withholding, late-filing penalties. | Remoto · HTTPVerifica live: accesso richiesto |
| LedgerIQ Depreciation CalculatorMACRS schedules, Section 179 and bonus depreciation with 2026 limits. | Remoto · HTTPVerifica live: accesso richiesto |
| LedgerIQ Entity Structure AnalyzerLLC vs S-corp vs C-corp federal tax comparison, S-corp savings and conversion steps. | Remoto · HTTPVerifica live: accesso richiesto |
| LedgerIQ Financial Ratio AnalyzerLiquidity, profitability and leverage ratios with plain-language readings. | Remoto · HTTPVerifica live: accesso richiesto |
| LedgerIQ Journal Entry AssistantPlain-English transactions to balanced journal entries, adjusting and closing entries. | Remoto · HTTPVerifica live: accesso richiesto |
| MCP Schema AuditAudits MCP tool definitions for patterns that make models call tools wrong or mis-fill args. | Remoto · HTTPVerifica live: accesso richiesto |
Altri server della categoria sviluppo
| Server | Esecuzione |
|---|---|
| GithubGitHub MCP - wraps the GitHub public REST API (no auth required for public endpoints) | Remoto · HTTPVerifica live: ✓ handshake |
| GithubGitHub analytics - repos, PRs, issues, releases, contributors. | Locale · stdio |
| Github ActionsGitHub Actions MCP - view runs, read logs, re-run jobs, and manage CI/CD. | Locale · stdio |
| GitHub Actions AuditGitHub Actions workflow security audit - 21 checks: pinning, permissions, secrets, injection. | Remoto · HTTPVerifica live: accesso richiesto |
| Github Analytics MCP ServerGet GitHub repository stats, search repos, analyze languages, and compare projects. | Locale · stdio |
| Github GistMCP server to create, read, update, list, and search GitHub Gists from your IDE. | Locale · stdio |
| GitHub Inside Claude CodeNormalized GitHub-CLI bridge for Claude Code - 89 ops, 6 families incl. federation sources. | Locale · stdio |
| Github Intel MCPGitHub repository intelligence: search repos, read repo details, and list user repos. No key... | Locale · stdio |