
Security News
GitHub Actions Adds cache-mode to Limit Cache Poisoning Risk
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.
dingdawg-devops-agent
Advanced tools
DevOps that remembers what broke last time. Deployment checks, incident response, infra review — patterns from past incidents prevent future ones.
Breakthrough deployment failures before they hit production. AI DevOps that learns YOUR infrastructure patterns.
AI-powered deployment verification, secret scanning, incident analysis, infrastructure auditing, runbook generation, and cost optimization. Catches leaked AWS keys, GitHub tokens, database URLs, and private keys. Free tier runs locally with zero data transmission. Every action is governed and receipted.
This MCP server returns structured JSON for seamless integration:
deploy_check pre-deploy -> secret_scan for leaked credentials -> infra_audit for config drift -> incident_analyze when issues arise -> runbook_generate for response procedures -> cost_optimize for spend reductionComposable with any MCP client: Claude Code, Cursor, VS Code, ChatGPT Desktop, Windsurf.
npx dingdawg-devops-agent
claude mcp add devops -- npx dingdawg-devops-agent
Add to .cursor/mcp.json:
{"mcpServers": {"devops": {"command": "npx", "args": ["dingdawg-devops-agent"], "env": {"DINGDAWG_API_KEY": "your-key"}}}}
npx dingdawg-setup
| Tool | Free Tier | Paid Tier |
|---|---|---|
deploy_check | 10/day, basic deploy verification | Unlimited, LLM-powered with rollback recommendations |
secret_scan | 10/day, 7 secret patterns (AWS, GitHub, JWT, etc.) | Unlimited, 50+ patterns with rotation guidance |
incident_analyze | 5/day, basic log analysis | Unlimited, AI-powered root cause analysis |
infra_audit | 5/day, config checklist | Unlimited, drift detection with remediation |
runbook_generate | 3/day, template-based | Unlimited, AI-generated context-aware runbooks |
cost_optimize | 3/day, basic spend analysis | Unlimited, AI-powered with savings projections |
Get API key: https://dingdawg.com/developers
Every call is receipted and auditable. Secret scans reference specific pattern types with zero false-positive-tolerant matching. Incident analyses include timeline reconstruction. Infrastructure audits reference CIS benchmark controls.
FAQs
Governance receipts for AI agents — DevOps deployment checks, incident response, and infra review, with signed audit receipts for every action, compliant with EU AI Act, Colorado AI Act (SB 24-205), and NIST AI RMF.
The npm package dingdawg-devops-agent receives a total of 20 weekly downloads. As such, dingdawg-devops-agent popularity was classified as not popular.
We found that dingdawg-devops-agent demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.

Company News
Allow myself to introduce... myself.

Research
/Security News
A Twitch browser extension on Chrome and Firefox forwards users’ live OAuth session tokens through proxies controlled by a Russian bot service.