Developer · Remote MCP server
GitHub Actions Audit
GitHub Actions workflow security audit - 21 checks: pinning, permissions, secrets, injection.
What the MCP Registry states
The entry as published to the official MCP Registry (read 2026-10-04), latest version.
- Registry name
io.github.UnbearableDev/github-actions-audit- Version
- 1.0.1
- Status
- Active
- Category
- developer
- Transport
- Streamable HTTP
- Published
- 2026-06-10
- Updated
- 2026-06-10
- Publisher
- UnbearableDev (GitHub) · 6 servers with pages here
- Listed under
- GitHub MCP servers, GitHub Actions MCP servers
- Repository
- github.com/UnbearableDev/github-actions-audit
- Source
- Registry API entry
Remote endpoints
| Transport | URL | Headers declared |
|---|---|---|
| Streamable HTTP | https://unbearable-dev--github-actions-audit.apify.actor/mcp | Authorization (required, secret) |
How to connect GitHub Actions Audit
GitHub Actions Audit is a remote MCP server: there is nothing to install. Its endpoint is https://unbearable-dev--github-actions-audit.apify.actor/mcp, served over Streamable HTTP. In an assistant that accepts remote MCP servers (often under a setting named connectors, integrations or tools), add a new server and give it this URL; in a client configured by file, add it as a remote (HTTP) server with the same URL.
The registry entry declares an HTTP header for the connection: Authorization (required, secret). A secret header usually carries an API key or token issued by the service; clients that accept custom headers set it with the server's URL.
Derived from the registry entry, not tested here. What the server does, and on what terms, is set by its publisher; check its repository or website before giving it access to your accounts or files. How to add an MCP server to an assistant · Before you connect
More from UnbearableDev (GitHub)
| Server | Runs |
|---|---|
| Docker Compose AuditSecurity audit for docker-compose.yml — 25 checks: secrets, privileges, network, volumes, images. | Remote · HTTP |
| Dockerfile AuditHadolint-grade Dockerfile audit — 19 checks: secrets, privileges, supply chain, hygiene. | Remote · HTTP |
| Hungarian Postcode ValidatorHungarian postcode lookup + validation - 3,484 codes, sub-10ms lookups, bulk address endpoint. | Remote · HTTP |
| IAC Audit PackFour IaC audits in one call: Compose, Dockerfile, GitHub Actions, Kubernetes. 131 checks. | Remote · HTTP |
| Kubernetes Manifest AuditKube-linter audit for Kubernetes manifests — 63 checks: security, availability, RBAC, network. | Remote · HTTP |
More developer servers
| Server | Runs |
|---|---|
| GitHubConnect AI assistants to GitHub - manage repos, issues, PRs, and workflows through natural language. | Remote & Local · HTTP, stdio |
| GithubGitHub MCP — wraps the GitHub public REST API (no auth required for public endpoints) | Remote · HTTP |
| GithubGitHub analytics - repos, PRs, issues, releases, contributors. | Local · stdio |
| Github ActionsGitHub Actions MCP — view runs, read logs, re-run jobs, and manage CI/CD. | Local · stdio |
| GitHub Actions Security AuditAudit GitHub Actions workflows for script injection, unpinned actions and missing permissions. | Remote · HTTP |
| Github Analytics MCP ServerGet GitHub repository stats, search repos, analyze languages, and compare projects. | Local · stdio |
| Github GistMCP server to create, read, update, list, and search GitHub Gists from your IDE. | Local · stdio |
| GitHub Inside Claude CodeNormalized GitHub-CLI bridge for Claude Code — 89 ops, 6 families incl. federation sources. | Local · stdio |