Local GitHub Actions/CI maintenance check (action pinning, token perms). Not a full security audit.
Local GitHub Actions/CI maintenance check (action pinning, token perms). Not a full security audit. Exposed over MCP by the taskbounty mcp server, that capability becomes something an assistant can invoke while it works, not something you go and do afterwards.
Want a human to interpret or fix what the Action surfaces? Request a free launch-safety review. TaskBounty gets no access to your repo, source, or workflows unless you submit that form.
Everything the assistant can do here goes through one of these:
uses — actions/checkout@v4run — npx taskbounty-check@0.1.6 . --github-summary --no-networkThird — party actions pinned to a movable tag/branch instead of a commit SHAContext — dependent workflow patterns flagged for private review (e.g. pull_request_target, script injection)Transmits — ** nothing by default. --share uploads nothing — it writes a *sanitized,Mode — Commandtaskbounty-check on npm is all you need. Most clients run it directly, so configuration is a few lines and a restart.
Plenty of developer tooling servers cover similar ground. The differences that matter in practice are scope of access and how much setup stands between you and a working tool call. Taskbounty's toolset — uses, run, Third and 3 more — is a fair guide to whether it matches your workflow. It is maintained by eliottreich; worth a glance at recent repository activity before you build anything load-bearing on it.
SyncDev reviews every entry in this directory against the project's own documentation before publishing, and revisits them as servers change.
| Tool | What it does |
|---|---|
| uses | actions/checkout@v4 |
| run | npx taskbounty-check@0.1.6 . --github-summary --no-network |
| Third | party actions pinned to a movable tag/branch instead of a commit SHA |
| Context | dependent workflow patterns flagged for private review (e.g. pull_request_target, script injection) |
| Transmits | ** nothing by default. **--share uploads nothing** — it writes a *sanitized, |
| Mode | Command |
{
"mcpServers": {
"taskbounty-check": {
"command": "npx",
"args": ["-y", "taskbounty-check"]
}
}
}Add to claude_desktop_config.json, then restart Claude Desktop.
Kill hallucinated APIs — version-accurate, up-to-date library documentation injected straight into context.
Microsoft's official browser automation server — drive a real browser through the accessibility tree, no screenshots needed.
GitHub's official server — repos, issues, pull requests, Actions and code security, straight from your assistant.
Issue tracking at the speed of conversation — Linear's official hosted server with OAuth and zero install.
Local repository surgery — status, diffs, commits, branches and history for any repo on disk.
Timezone sanity for AI — current time anywhere and correct conversions, without the model doing date math.