Skip to main content
{ Reporting and Compliance }

GitHub Public Repository Posture Audit

Reports the public repositories in a GitHub organization that fail its security policy, with each failing check.

What this agent does

This read-only agent audits every public repository in a GitHub organization against the organization's security policy. It checks branch protection, the README, the license, public exposure, the Actions token, and outside collaborator access. It then reports each repository that fails, with the checks it fails.

The challenge

A public repository exposes its code, its workflows, and its access settings to everyone. Repositories are made public by mistake, and protections change after a repository is created. A default branch loses its review rule, an outside collaborator keeps write access, or Actions gets a write token by default. Nobody checks every public repository against the policy. Teams learn about these gaps only when someone finds one by chance.

The solution

The agent checks every public repository against the same short policy on each run. It reports a check it cannot complete as inconclusive, never as a violation. It refuses to report when the repository list is incomplete, so it never presents a partial scan as the whole organization. Provides a unified list of noncompliant public repositories and the checks to fix.

Workflow

  1. 01

    List repositories

    List every public, non-archived repository in the organization, and stop when the list is incomplete.

  2. 02

    Check policy

    Check each repository for branch protection, a README, a license, an approved public listing, a read-only Actions token, and outside collaborator access.

  3. 03

    Report

    Report each noncompliant repository with its failing checks, and track the noncompliant and total counts.

Agent template

# GitHub Public Repository Posture Audit

## Measurable outcomes

Every public repository in the organization that fails the security policy is in the report, with each check it fails. Track the noncompliant count on every run. The count falls as owners fix their repositories.

## Procedure

For a given organization, list every public, non-archived repository. Stop and report the failure when the list is shorter than expected. Never present a partial list as the whole organization. Check each repository against six rules. The default branch is protected and requires a pull request with at least one approving review. A README exists at the root. A license exists at the root. The repository is on an allowlist of repositories approved to be public. The Actions default token permission is read-only. No outside collaborator has push access or higher. A repository that fails any rule is noncompliant. When a setting cannot be read, report the check as inconclusive and a token scope problem, not a violation. I maintain the allowlist, and I add a repository only after I review its public exposure.

## Requirements

It needs GitHub API read access to the organization's repositories, their branch protection, Actions settings, and collaborators, and nothing more. It never changes a repository, its settings, or its collaborators.