One FOXIFY authority system. Start free → 99-Star Quick Check → runtime preflight → scoped human review → monitoring only when ongoing coverage is needed.
CI AUTHORITY PREFLIGHT

GitHub Agent Authority Action

Map agent authority in CI without pretending every match is a vulnerability.

FOXIFY Agent Authority Check is a dependency-free GitHub Action for MCP servers and tool-using AI agents. It inventories authority-bearing code paths and produces evidence JSON plus a deterministic evidence hash. It does not assign invented severity to a regex hit or execute the target repository.

Drop it into a workflow

name: Agent Authority Check

on:
  pull_request:
  push:
    branches: [main]

jobs:
  authority-preflight:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: speeedy10/agent-authority-check@v1
        with:
          path: .
          output: foxify-authority.json
      - uses: actions/upload-artifact@v4
        with:
          name: foxify-authority-evidence
          path: foxify-authority.json

What the Action reports

The evidence boundary

The Action deliberately returns OBSERVATIONS_ONLY. A source match does not prove a vulnerability. FOXIFY promotes a security finding only when the primitive, reachability and consequence chain is established.

Why teams put this in CI

Agent authority can change quietly when a pull request adds a new tool, widens credential scope, introduces shell or browser automation, or connects code to a payment or deployment surface. The Action gives reviewers a stable authority-oriented diff signal before that code reaches production, without executing the repository or requiring secrets.

The evidence artifact can also be retained with the build so a later review can compare what authority-bearing surfaces existed at a specific commit. That makes it useful as a preflight and audit input rather than a substitute for human security judgment.

From free CI to a bounded answer

Open the GitHub Action and source →

See the synthetic Quick Check report →

Run a 99-Star Quick Check for one public GitHub repository →

For production or explicitly authorized agent boundaries, use the human Authority Review or the runtime action preflight.