nomarj/Sigil Security Scan

Scan your repository for malicious patterns in AI agent code, MCP servers, and packages

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
pathPath to scan (relative to repository root)no.
thresholdMinimum verdict level to fail the action (low/medium/high/critical)nomedium
api-keySigil cloud API key for threat intel enrichment (optional)no""
fail-on-findingsWhether to fail the action when findings exceed the thresholdnotrue
phasesComma-separated list of scan phases to run (all, install-hooks, code-patterns, network, credentials, obfuscation, provenance)noall
excludeGlob patterns to exclude from scanning (comma-separated)no""
namedescription
verdictScan verdict (clean, low, medium, high, critical)
risk-scoreNumeric risk score from the scan
findings-countTotal number of findings detected