
Company News
Jerod Santo Joins Socket as Head of Media
Allow myself to introduce... myself.
taskbounty-check
Advanced tools
Pre-launch safety check for AI-built apps (Lovable, Bolt, Replit, Cursor, v0). Scans your GitHub Actions + CI hygiene locally. Source code and workflow contents never leave your machine.
Pre-launch safety check for AI-built apps. Built it with Lovable, Bolt, Replit, Cursor, or v0? This scans your GitHub Actions + CI hygiene locally before you ship. Your source code and workflow contents never leave your machine. Network is off by default.
Scope, honestly: this checks GitHub Actions workflow + update-automation hygiene. It does not check exposed secrets, auth, payments, webhooks, or runtime behavior — those need a manual review. It is a maintenance check, not a full security audit.
Upload status: automatic upload (
--share→ API) is disabled during the pilot.--shareonly produces a sanitized summary for you to paste into TaskBounty.
# 1. Scan the current repo locally (no network, writes a local report)
npx taskbounty-check@latest .
# 2. SARIF for GitHub Code Scanning
npx taskbounty-check@latest . --format sarif --output taskbounty.sarif
# 3. Scaffold a least-privilege CI workflow (previews; never overwrites)
npx taskbounty-check@latest init
# 4. Local MCP server for Codex / Claude Code / Cursor
npx taskbounty-check@latest mcp
Reproducible, pinned invocation (recommended): npx taskbounty-check@0.1.2 .
Privacy: the scan runs locally and sends nothing by default. Source code, workflow contents, filenames, line numbers, and evidence never leave your machine. The only thing that can ever be transmitted is a sanitized counts-only summary, and only when you explicitly choose to.
Checks (GitHub Actions + CI maintenance hygiene):
permissions: blockpull_request_target, script injection)Does NOT check (these need a manual review): exposed secrets, auth/authorization, payments, webhooks, runtime behavior. It is a maintenance/hygiene check, not a full security audit or a penetration test.
| Mode | Command | Network |
|---|---|---|
| Single repo | npx taskbounty-check . | none |
| Directory of repos | npx taskbounty-check ./all-repos | none |
| Explicit paths | npx taskbounty-check --manifest repos.json | none |
GitHub org (your gh session) | npx taskbounty-check --gh-org <org> | yes, opt-in |
--gh-org uses your existing gh CLI session to fetch each repo's workflow files to this
machine (read-only). Your GitHub token is never read by this tool and never sent to TaskBounty.
Run --explain-data to print this at any time.
<repo>/.github/workflows/*.yml|*.yaml and
update-automation config (dependabot.yml/renovate.json*). Never source files, .env,
secrets, SSH keys, credential stores, or anything outside the selected repository roots.
Symlinks that escape a root are skipped, never followed.<out>.json (full detail) and <out>.html.--share produces a sanitized summary (scan id, label, candidate
counts by category, private-review count, scanner version, timestamps; repo names only with
--include-repo-names) that you copy and paste into TaskBounty yourself. Automatic upload is
disabled during the pilot.--share · --gh-org <org> · --manifest <file> · --org-label <label> ·
--include-repo-names · --dry-run · --explain-data · --delete-local-report ·
--no-network (default unless --share/--gh-org) · --out <basename> · --version · --help
Request a free 20-minute launch-safety review: https://www.task-bounty.com/ai-app-security-check/review?utm_source=npm&utm_medium=npm_readme&utm_campaign=workflow_security
TaskBounty receives nothing unless you submit that form. The scan runs locally and the full report stays on your machine; the review form gives us no access to your repositories, source, workflows, or secrets.
Emit SARIF 2.1.0 and surface findings in your repo's Security → Code scanning tab:
npx taskbounty-check@latest . --format sarif --output taskbounty.sarif
The SARIF carries deterministic rule ids (taskbounty/<rule>), severity levels, and file/line
references — no source contents, secrets, or environment values, and no network access.
Confirmed findings are emitted as kind: fail; lower-confidence items as kind: review.
Help interpreting SARIF results: https://www.task-bounty.com/ai-app-security-check/review?utm_source=github&utm_medium=sarif_docs&utm_campaign=workflow_security
Upload it with the official action (full example in examples/code-scanning.yml):
permissions:
contents: read
security-events: write
steps:
- uses: actions/checkout@v4
- run: npx taskbounty-check@latest . --format sarif --output taskbounty.sarif
- uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: taskbounty.sarif
Run a local stdio MCP server so Codex, Claude Code, or Cursor can scan and reason about findings
in your editor. It runs locally, makes zero outbound network requests, uploads no source, and
never modifies files — generate_fix_plan returns a plan as text for you to apply yourself.
npx taskbounty-check@latest mcp
Tools: scan_repo (local scan summary), explain_finding (plain-language explanation), generate_fix_plan (text fix plan).
Want a human to review the plan? https://www.task-bounty.com/ai-app-security-check/review?utm_source=mcp&utm_medium=mcp_docs&utm_campaign=workflow_security
Cursor — .cursor/mcp.json:
{ "mcpServers": { "taskbounty-check": { "command": "npx", "args": ["-y", "taskbounty-check@latest", "mcp"] } } }
Claude Code:
claude mcp add taskbounty-check -- npx -y taskbounty-check@latest mcp
Codex — in ~/.codex/config.toml:
[mcp_servers.taskbounty-check]
command = "npx"
args = ["-y", "taskbounty-check@latest", "mcp"]
Zero runtime dependencies. Published with npm provenance; verify checksums. See the threat model
(design-docs/security-cli-threat-model.md) and external-review packet
(design-docs/security-expansion/external-review-packet.md) in the project repository.
FAQs
Pre-launch safety check for AI-built apps (Lovable, Bolt, Replit, Cursor, v0). Scans your GitHub Actions + CI hygiene locally. Source code and workflow contents never leave your machine.
The npm package taskbounty-check receives a total of 22 weekly downloads. As such, taskbounty-check popularity was classified as not popular.
We found that taskbounty-check demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Allow myself to introduce... myself.

Research
/Security News
A Twitch browser extension on Chrome and Firefox forwards users’ live OAuth session tokens through proxies controlled by a Russian bot service.

Security News
Anthropic found biased reasoning and recklessness drove Claude Mythos 5 to publish malware on PyPI and compromise a security vendor.