Taskbounty Check MCP Server
A local check for GitHub Actions and CI maintenance hygiene (third-party action pinning, workflow token permissions, and update automation), built for apps shipped with Lovable, Bolt, Replit, Cursor, or v0.
People connecting DevOps & monitoring tools to Claude, Cursor, VS Code, or another MCP client. The project is written in JavaScript.
VERIFIED ACTIVE
LAST COMMIT 2026-06-21 · ★ 2 · #73 OF 101 MAINTAINED DEVOPS & MONITORING · VERIFIED 2026-08-25
MIT · JavaScript servers · how we verify → /methodology
01 · Install Taskbounty Check
before you install - you'll need
The README does not document required environment variables for a basic install.
Claude Code
claude mcp add eliottreich-taskbounty-check -- npx -y taskbounty-check Claude Desktop / Cursor / VS Code - add to config
{
"mcpServers": {
"eliottreich-taskbounty-check": {
"command": "npx",
"args": [
"-y",
"taskbounty-check"
]
}
}
} Same JSON for Cursor. For VS Code, rename the top-level key from `mcpServers` to `servers`.
Using another client? Same JSON, different key
Claude Desktop · mcpServers
Cursor · mcpServers
VS Code · servers
Windsurf · mcpServers
Zed · context_servers
Cline · mcpServers
Roo Code · mcpServers
Continue · mcpServers
LibreChat · mcpServers
Gemini CLI · mcpServers
Codex CLI · mcp_servers
Full setup guides: every client.
02 · Evidence
Security posture
What to check before giving this server access to your agent - from the registry, GitHub, and our own probes. We don't score safety; we show what's verifiable.
runs as local process (stdio) - runs on your machine with your user's permissions
license MIT - declared in the repository
npm package taskbounty-check - unscoped; check the name against the project README before installing
registry namespace io.github.eliottreich is GitHub-verified and matches the repo owner
03 · What Taskbounty Check can do
Prose above is summarized from the project's README and registry record - no invented capabilities.
Latest releases
v0.1.6 · 2026-06-21
Fixed · Ignore YAML-looking test fixtures and heredocs inside workflow scripts when checking live uses and permissions keys. · Keep detection unchanged for genuine workflow configuration. · Keep the website scanner…
v0.1.5 · 2026-06-21
Distribution release. Official MCP Registry (server.json), agent skill (skills.sh), product-led MCP CTA (shown once on findings), SARIF rule helpUri linking the methodology, discovery keywords/topics, reworked README +…
v0.1.4 · 2026-06-21
Reliability patch. SHA-pinned init workflow (no @latest); --share keeps the network guard and uploads nothing; only --gh-org uses the network; honest network wording (defense in depth, not a complete sandbox).…
04 · Who maintains Taskbounty Check
taskbounty-check is maintained by eliottreich. We track 2 MCP servers from eliottreich - 2 actively maintained, 3 combined GitHub stars, oldest repo from May 2026.
05 · Facts
- repository
- github.com/eliottreich/taskbounty-check
- category
- DevOps & monitoring - ranked #73 of 101 actively-maintained DevOps & monitoring servers as of 2026-08-25.
- release cadence
- 6 releases in the last 90 days (latest 2026-06-21)
- registry
- io.github.eliottreich/taskbounty-check (active, first published 2026-06-21 · 2 versions)
- packages
- npm:taskbounty-check
06 · Taskbounty Check FAQ
What is Taskbounty Check?
A local check for GitHub Actions and CI maintenance hygiene (third-party action pinning, workflow token permissions, and update automation), built for apps shipped with Lovable, Bolt, Replit, Cursor, or v0.
Is Taskbounty Check still maintained?
Yes - as of 2026-08-25, its last commit was 2026-06-21 and it shipped 6 releases in the last 90 days. We re-verify nightly.
How do I install Taskbounty Check?
Run `npx -y taskbounty-check`. The README does not document required environment variables for a basic install. You can also paste the ready-made client config above.
Does Taskbounty Check run locally?
Yes - it's a stdio server: it runs on your machine (via npx) with your user's permissions. Your data stays local unless the server itself calls external APIs.
07 · Alternatives to Taskbounty Check
Alternatives to Taskbounty Check
Maintained DevOps & monitoring servers if Taskbounty Check isn't the fit.
- World Monitor Live global intelligence: real-time markets, conflicts, country risk, chokepoints, energy. 39 tools. ★ 83,963 · 2026-08-24
- Open Metadata Official OpenMetadata MCP: governed context and business semantics for AI assistants and agents. ★ 14,959 · 2026-08-25
- Kubeshark MCP Server Real-time Kubernetes network traffic visibility and API analysis for HTTP, gRPC, Redis, Kafka, DNS. ★ 12,057 · 2026-08-18
- Grafana An MCP server giving access to Grafana dashboards, data and more. ★ 3,384 · 2026-08-24
- Radar Kubernetes visibility for AI agents: query workloads, events, logs, topology, and Helm releases. ★ 3,103 · 2026-08-24
- Testkube MCP MCP server for Testkube - Manage test workflows, executions, and artifacts via AI assistants ★ 1,647 · 2026-08-24
Pairs well with
Servers that cover what Taskbounty Check doesn't - only shown when the pairing reason fits the companion.
More DevOps & monitoring MCP servers · Go Model · Log Analyzer MCP · Duplicacy MCP · Spinnaker MCP
More JavaScript MCP servers · ellmos FileCommander · Ux MCP Server · Analytics · Cernion Energy Tools MCP · Metabase AI Assistant · see all