Scorecard inspects the project's GitHub Actions workflows for two dangerous patterns: an untrusted code checkout, where a pull_request_target or workflow_run trigger (which runs with write permission and access to the target repository's secrets) is combined with an explicit checkout of the pull request's code; and script injection, where an inline script interpolates attacker-controllable context values such as an issue title so that they may execute on the runner. Full marks require every workflow to avoid both patterns. The check does not recognise safe uses, such as a checkout gated on a maintainer label.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.