Taskbounty MCP Server

Local GitHub Actions/CI maintenance check (action pinning, token perms). Not a full security audit.

Local serverstdio

What is the Taskbounty MCP server?

Local GitHub Actions/CI maintenance check (action pinning, token perms). Not a full security audit. Exposed over MCP by the taskbounty mcp server, that capability becomes something an assistant can invoke while it works, not something you go and do afterwards.

What it actually does

Want a human to interpret or fix what the Action surfaces? Request a free launch-safety review. TaskBounty gets no access to your repo, source, or workflows unless you submit that form.

  • Reads only your GitHub Actions workflow files and update-automation config, scans them

Its toolset

Everything the assistant can do here goes through one of these:

  • uses — actions/checkout@v4
  • run — npx taskbounty-check@0.1.6 . --github-summary --no-network
  • Third — party actions pinned to a movable tag/branch instead of a commit SHA
  • Context — dependent workflow patterns flagged for private review (e.g. pull_request_target, script injection)
  • Transmits — ** nothing by default. --share uploads nothing — it writes a *sanitized,
  • Mode — Command

Adding it to your client

taskbounty-check on npm is all you need. Most clients run it directly, so configuration is a few lines and a restart.

When to reach for it

Plenty of developer tooling servers cover similar ground. The differences that matter in practice are scope of access and how much setup stands between you and a working tool call. Taskbounty's toolset — uses, run, Third and 3 more — is a fair guide to whether it matches your workflow. It is maintained by eliottreich; worth a glance at recent repository activity before you build anything load-bearing on it.

SyncDev reviews every entry in this directory against the project's own documentation before publishing, and revisits them as servers change.

Caveats

  • It runs with your machine's permissions. That is convenient and also the reason to think about what you point it at before you approve a tool call.
  • MCP clients confirm each tool call by default. Leave that on until you have watched what the taskbounty mcp server does with a few real requests.

Available tools

ToolWhat it does
usesactions/checkout@v4
runnpx taskbounty-check@0.1.6 . --github-summary --no-network
Thirdparty actions pinned to a movable tag/branch instead of a commit SHA
Contextdependent workflow patterns flagged for private review (e.g. pull_request_target, script injection)
Transmits** nothing by default. **--share uploads nothing** — it writes a *sanitized,
ModeCommand

How to install the Taskbounty MCP server

{
  "mcpServers": {
    "taskbounty-check": {
      "command": "npx",
      "args": ["-y", "taskbounty-check"]
    }
  }
}

Add to claude_desktop_config.json, then restart Claude Desktop.

Example prompts to try

  • Use Taskbounty to uses.
  • Use Taskbounty to run.
  • Use Taskbounty to Third.

Frequently asked questions

It connects Taskbounty to MCP-compatible AI assistants such as Claude and Cursor, exposing 6 tools (uses, run, Third, and more) that the assistant can call on your behalf. Instead of copying data back and forth by hand, the assistant works with Taskbounty directly.