Scans GitHub Actions workflow files for dangerous triggers, template injection, unpinned actions, excessive permissions, and secrets in shell commands before they are committed, exposing the checks as MCP tools for agents.
Security auditor for CI ecosystems that detects supply-chain and injection flaws in CI/CD configuration files across seven CI platforms, providing taint analysis, remediation, and compliance scoring.
Local-only GitHub Actions and CI maintenance scanner for AI-built apps. Exposes scan, explanation, and fix-planning tools to MCP clients; modifies nothing and makes no outbound requests by default.
Automated security audit assistant for GitHub repositories that detects static vulnerabilities (leaked credentials, vulnerable dependencies, bad Docker practices, excessive GitHub Actions permissions), calculates a security score, and provides risk explanations and mitigation recommendations via Cohere.