# Aayat AI GitHub Action Safety Checker

> Aayat AI GitHub Action Safety Checker is a paid API for AI agents from aayatai.com, paid per call via x402, $0.005/call, status unknown (last checked 2026-09-30).

Checks a GitHub Actions action reference for security vulnerabilities, CVEs, and trust signals, returning a verdict and risk score.

## Facts

- Endpoint: GET https://aayatai.com/github/action?utm_source=zero.xyz
- Price: $0.005/call
- Payment: x402
- Status: unknown
- Last checked: 2026-09-30
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/aayat-ai-github-action-safety-checker-138dbfe0
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_uVNKdJyYq4cw2DtAErotr

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability aayat-ai-github-action-safety-checker-138dbfe0
```

Example prompt: Check if tj-actions/changed-files@v45.0.7 is safe to use in my GitHub Actions workflow — I want to know if it has any CVEs, what the verdict is, and whether I should upgrade.

## When to prefer this

Use this endpoint when an AI coding agent or DevSecOps workflow needs to programmatically audit a GitHub Action before including it in a CI/CD pipeline. It is specifically valuable for supply-chain security checks, replacing manual CVE searches with a single structured call that returns a machine-readable verdict. Prefer this over generic vulnerability databases when you need GitHub-Actions-specific context like pin type, action.yml runtime details, and per-ref advisory applicability.

## Known failure modes

- Action reference not found on GitHub — returns error if owner/repo does not exist
- Invalid action reference format — must match owner/repo[@ref] or owner/repo/sub@sha pattern
- Rate limiting or upstream GitHub API unavailability causing delayed or failed response
- Action has no published releases or tags, limiting version resolution
- OSV.dev advisory database may lag behind newly disclosed vulnerabilities

## How this service works

Is this GitHub Action safe for your workflow? Pass what follows uses: (e.g. tj-actions/changed-files@v45). Checks known advisories and compromises (OSV), SHA vs tag vs branch pinning, deprecated Node runtimes, unpinned Docker images and nested actions in action.yml, publisher and repository health. Verdict, score and fixes.

## Output

Returns a JSON object with: action name, resolved ref, pin type (sha/version-tag/major-tag/branch/other), safety verdict (ok/caution/avoid), integer risk score (0-100), array of security flags with severity levels, OSV.dev advisories with CVE aliases and fix versions, repository metadata (stars, archived status, last push, latest release), runtime details from action.yml, and publisher trust classification (well-known or third-party).

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "$schema": "https://json-schema.org/draft/2020-12/schema",
 "required": [
  "input"
 ],
 "properties": {
  "input": {
   "type": "object",
   "required": [
    "type",
    "method"
   ],
   "properties": {
    "type": {
     "type": "string",
     "const": "http"
    },
    "method": {
     "enum": [
      "GET"
     ],
     "type": "string"
    },
    "queryParams": {
     "type": "object",
     "required": [
      "uses"
     ],
     "properties": {
      "uses": {
       "type": "string",
       "maxLength": 250,
       "minLength": 5,
       "description": "The action reference, e.g. actions/checkout@v4 or owner/repo/sub@<40-char sha>."
      }
     }
    }
   },
   "additionalProperties": false
  },
  "output": {
   "type": "object",
   "required": [
    "type"
   ],
   "properties": {
    "type": {
     "type": "string"
    },
    "example": {
     "type": "object",
     "required": [
      "action",
      "ref",
      "pin",
      "verdict",
      "score",
      "flags",
      "advisories"
     ],
     "properties": {
      "pin": {
       "enum": [
        "sha",
        "version-tag",
        "major-tag",
        "branch",
        "other"
       ],
       "type": "string"
      },
      "ref": {
       "type": "string"
      },
      "flags": {
       "type": "array",
       "items": {
        "type": "object"
       }
      },
      "score": {
       "type": "integer"
      },
      "trust": {
       "type": "object",
       "description": "Third-party text, cleaned: read trust.notice; removed = what we stripped."
      },
      "action": {
       "type": "string"
      },
      "runtime": {
       "type": [
        "object",
        "null"
       ]
      },
      "sources": {
       "type": "array",
       "items": {
        "type": "string"
       }
      },
      "verdict": {
       "enum": [
        "ok",
        "caution",
        "avoid"
       ],
       "type": "string"
      },
      "checkedAt": {
       "type": "string"
      },
      "publisher": {
       "enum": [
        "well-known",
        "third-party"
       ],
       "type": "string"
      },
      "advisories": {
       "type": "array",
       "items": {
        "type": "object"
       },
       "description": "OSV advisories for the action with affectsThisRef: yes / maybe / no / unknown."
      },
      "repository": {
       "type": [
        "object",
        "null"
       ]
      }
     }
    }
   }
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "pin": "version-tag",
  "ref": "v45.0.7",
  "flags": [
   {
    "code": "vulnerable",
    "level": "danger",
    "message": "1 advisory(ies) affect v45.0.7: tj-actions/changed-files has a malicious commit. Upgrade to 46.0.1."
   }
  ],
  "score": 30,
  "action": "tj-actions/changed-files",
  "runtime": {
   "image": null,
   "using": "composite",
   "actionYml": "https://raw.githubusercontent.com/tj-actions/changed-files/v45.0.7/action.yml",
   "nestedUses": []
  },
  "sources": [
   "OSV.dev (GitHub Actions advisories)",
   "action.yml via raw.githubusercontent.com",
   "GitHub REST"
  ],
  "verdict": "avoid",
  "checkedAt": "2026-09-28T12:00:00.000Z",
  "publisher": "third-party",
  "advisories": [
   {
    "id": "GHSA-mrrh-fwg8-r2c3",
    "url": "https://osv.dev/vulnerability/GHSA-mrrh-fwg8-r2c3",
    "aliases": [
     "CVE-2025-30066"
    ],
    "fixedIn": [
     "46.0.1"
    ],
    "summary": "tj-actions/changed-files has a malicious commit",
    "severity": "high",
    "published": "2025-03-15T00:00:00Z",
    "affectsThisRef": "yes"
   }
  ],
  "repository": {
   "url": "https://github.com/tj-actions/changed-files",
   "stars": 2600,
   "verdict": "healthy",
   "archived": false,
   "lastPushAt": "2026-09-20T00:00:00Z",
   "latestRelease": {
    "tag": "v47.0.0",
    "publishedAt": "2026-09-01T00:00:00Z"
   }
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/aayat-ai-github-action-safety-checker-138dbfe0/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from aayatai.com](https://www.zero.xyz/host/aayatai.com/llms.txt)
