{"uid":"cap_uVNKdJyYq4cw2DtAErotr","slug":"aayat-ai-github-action-safety-checker-138dbfe0","name":"Aayat AI GitHub Action Safety Checker","description":"Is this GitHub Action safe for your workflow? Pass what follows uses: (e.g. tj-actions/changed-files@v45). Checks known advisories and compromises (OSV), SHA vs tag vs branch pinning, deprecated Node runtimes, unpinned Docker images and nested actions in action.yml, publisher and repository health. Verdict, score and fixes.","url":"https://aayatai.com/github/action?utm_source=zero.xyz","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","required":["uses"],"properties":{"uses":{"type":"string","maxLength":250,"minLength":5,"description":"The action reference, e.g. actions/checkout@v4 or owner/repo/sub@<40-char sha>."}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object","required":["action","ref","pin","verdict","score","flags","advisories"],"properties":{"pin":{"enum":["sha","version-tag","major-tag","branch","other"],"type":"string"},"ref":{"type":"string"},"flags":{"type":"array","items":{"type":"object"}},"score":{"type":"integer"},"trust":{"type":"object","description":"Third-party text, cleaned: read trust.notice; removed = what we stripped."},"action":{"type":"string"},"runtime":{"type":["object","null"]},"sources":{"type":"array","items":{"type":"string"}},"verdict":{"enum":["ok","caution","avoid"],"type":"string"},"checkedAt":{"type":"string"},"publisher":{"enum":["well-known","third-party"],"type":"string"},"advisories":{"type":"array","items":{"type":"object"},"description":"OSV advisories for the action with affectsThisRef: yes / maybe / no / unknown."},"repository":{"type":["object","null"]}}}}}}},"responseSchema":{"type":"json","example":{"pin":"version-tag","ref":"v45.0.7","flags":[{"code":"vulnerable","level":"danger","message":"1 advisory(ies) affect v45.0.7: tj-actions/changed-files has a malicious commit. Upgrade to 46.0.1."}],"score":30,"action":"tj-actions/changed-files","runtime":{"image":null,"using":"composite","actionYml":"https://raw.githubusercontent.com/tj-actions/changed-files/v45.0.7/action.yml","nestedUses":[]},"sources":["OSV.dev (GitHub Actions advisories)","action.yml via raw.githubusercontent.com","GitHub REST"],"verdict":"avoid","checkedAt":"2026-09-28T12:00:00.000Z","publisher":"third-party","advisories":[{"id":"GHSA-mrrh-fwg8-r2c3","url":"https://osv.dev/vulnerability/GHSA-mrrh-fwg8-r2c3","aliases":["CVE-2025-30066"],"fixedIn":["46.0.1"],"summary":"tj-actions/changed-files has a malicious commit","severity":"high","published":"2025-03-15T00:00:00Z","affectsThisRef":"yes"}],"repository":{"url":"https://github.com/tj-actions/changed-files","stars":2600,"verdict":"healthy","archived":false,"lastPushAt":"2026-09-20T00:00:00Z","latestRelease":{"tag":"v47.0.0","publishedAt":"2026-09-01T00:00:00Z"}}}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.005","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.005/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.005","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.005","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_QNP4-jHqdSAckT33iiXHO","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.005","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Checks a GitHub Actions action reference for security vulnerabilities, CVEs, and trust signals, returning a verdict and risk score.","exampleAgentPrompt":"Check if tj-actions/changed-files@v45.0.7 is safe to use in my GitHub Actions workflow — I want to know if it has any CVEs, what the verdict is, and whether I should upgrade.","exampleUseCases":[{"title":"Audit CI pipeline before merging PR","prompt":"Before I merge this PR, check whether actions/checkout@v4 is safe — is it pinned properly, does it have any known vulnerabilities, and is the publisher well-known?"},{"title":"Investigate compromised action report","prompt":"I heard tj-actions/changed-files had a malicious commit — can you check the safety of tj-actions/changed-files@v45.0.7 and tell me if it affects that version and what I should upgrade to?"},{"title":"Validate SHA-pinned action in monorepo","prompt":"We pin all our actions to full SHAs for security — can you verify that actions/cache@d4323d4022d34567b4cc1c7c1b4b3a14f8c7b8d2 is safe and not associated with any advisories?"}],"resultDescription":"Returns a JSON object with: action name, resolved ref, pin type (sha/version-tag/major-tag/branch/other), safety verdict (ok/caution/avoid), integer risk score (0-100), array of security flags with severity levels, OSV.dev advisories with CVE aliases and fix versions, repository metadata (stars, archived status, last push, latest release), runtime details from action.yml, and publisher trust classification (well-known or third-party).","failureModes":["Action reference not found on GitHub — returns error if owner/repo does not exist","Invalid action reference format — must match owner/repo[@ref] or owner/repo/sub@sha pattern","Rate limiting or upstream GitHub API unavailability causing delayed or failed response","Action has no published releases or tags, limiting version resolution","OSV.dev advisory database may lag behind newly disclosed vulnerabilities"],"whenToPreferThis":"Use this endpoint when an AI coding agent or DevSecOps workflow needs to programmatically audit a GitHub Action before including it in a CI/CD pipeline. It is specifically valuable for supply-chain security checks, replacing manual CVE searches with a single structured call that returns a machine-readable verdict. Prefer this over generic vulnerability databases when you need GitHub-Actions-specific context like pin type, action.yml runtime details, and per-ref advisory applicability.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-02T18:41:00.712Z","isFirstParty":false,"canonicalSlug":"aayat-ai-github-action-safety-checker-138dbfe0"}