sungho-pk42ac/AgentGuard

Team-ready PR diff gate for AI-agent secrets, risky MCP/config changes, and SARIF evidence.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
base-shaBase commit SHA for the pull request diff.yes
head-shaHead commit SHA for the pull request diff.yes
report-pathMarkdown report file path to write and publish as a PR comment/artifact.noagent-risk-report.md
json-pathJSON findings file path to write.noagent-risk-findings.json
sarif-pathSARIF file path to write for GitHub code scanning upload.noagentguard.sarif
policy-pathOptional agent-policy.yaml/json path.no""
package-versionnpm package version or dist-tag to install.nolatest
fail-onGate threshold. Use block to fail only the score-based BLOCK verdict, review to fail any non-pass verdict, or never to report only.noblock
namedescription
conclusionpass, review, or block based on AgentGuard findings.
report-pathPath to the markdown AgentGuard report artifact.
json-pathPath to the JSON AgentGuard findings artifact.
sarif-pathPath to the SARIF AgentGuard artifact.
finding-countTotal non-advisory AgentGuard findings count.
advisory-countAdvisory AgentGuard findings count excluded from gate scoring.
review-countNon-advisory medium/high/critical findings count for workflow routing; conclusion remains score-based.
block-countWeighted non-advisory finding score used for BLOCK routing.