pezhik/SkillTotal AI Component Security Scan

Static security scan for AI components (MCP, agent skills, npm/PyPI, repos) - SARIF, deterministic, offline.

View on GitHub

Trust Signals

Scorecard Score
Scorecard 6–8scored Jul 9, 2026
Maintenance Recency
Activelast commit Jul 9, 2026
License
Apache 2.0

Pinned Snippet

workflow.ymlSHA-pinned
uses: pezhik/skilltotal@7905d363ef9bb525ebb119cbc008e961c4517a5f # v0.38.0

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
sourceWhat to scan: a path in the repo (default '.'), a git URL, or an npm:/pypi:<name> spec.no.
versionPin the skilltotal PyPI version to install. Empty installs the latest release.no""
fail-onFail the job when a finding is this severity or higher: 'high' or 'none'.nohigh
upload-sarifUpload SARIF to GitHub Code Scanning (job needs 'security-events: write').notrue
comment-on-prPost a summary comment on pull requests (job needs 'pull-requests: write').nofalse
baselineOptional path to a baseline file to suppress accepted findings.no""
sarif-fileWhere to write the SARIF report.noskilltotal.sarif
namedescription
sarif-filePath to the generated SARIF report.
risk-scoreRisk score, 0-100.
risk-levelRisk level: low / medium / high / critical.