Skip to content

CI integration

GitHub Action

name: MCP posture
on:
  schedule: [{cron: "0 6 * * 1"}]
  pull_request:
    paths: ["mcp-servers.txt", "mcp-posture.toml", ".mcp-posture-ignore", "mcp-posture.lock.json"]

permissions:
  contents: read
  security-events: write   # SARIF upload to code scanning

jobs:
  scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: batou9150/mcp-posture@main   # pin to a release tag or commit SHA
        with:
          targets-file: mcp-servers.txt
          fail-on: high
          baseline: mcp-posture.lock.json
          token: ${{ secrets.MCP_SCAN_TOKEN }}   # optional, to list tools behind auth
Input Default
targets URLs, one per line (# comments allowed)
config ./mcp-posture.toml config file
targets-file file with one URL per line; SARIF results point to its lines
fail-on high minimum severity that fails the step
baseline lock file from mcp-posture pin
token bearer token, passed to the scanner through the environment, never logged
args extra mcp-posture scan arguments
upload-sarif true upload to code scanning
sarif-category mcp-posture code scanning category
job-summary true append the Markdown report to the job summary
fail true fail the step on blocking findings

Outputs: exit-code, sarif-file, json-file. The SARIF upload and the job summary run even when findings fail the step.

Exit codes

Code Meaning
0 no unsuppressed finding at or above --fail-on, every target reachable
1 at least one unsuppressed finding at or above --fail-on
2 usage or configuration error
3 a target was unreachable (and no blocking finding)

Other CI systems

uvx mcp-posture scan \
  --targets-file mcp-servers.txt --sarif mcp-posture.sarif --markdown mcp-posture.md

GitLab, Azure DevOps and others ingest the SARIF file directly; the Markdown file is ready to post as a merge-request comment.