A GitHub Action
- uses: catidegla/mcpaudit@v0.1.1
with:
path: .
fail-on: high
- uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: mcpaudit.sarifSARIF is written before the exit code is decided, because the annotations on the diff are the useful part and they have to exist even when the scan fails the job.
CI drives the action over both corpora on every commit. The poisoned manifest has to fail it, and the benign corpus has to come back empty at the lowest threshold. The second half is the one that decides whether anybody keeps a scanner installed.
No change to the scanner itself. 37 tests.