WorkflowGuard is a prepared deterministic API for static preflight checks of GitHub Actions workflow YAML.
It returns structured findings for:
- missing or broad
GITHUB_TOKENpermissions - third-party actions not pinned to a full commit SHA
- privileged
pull_request_targetcheckout patterns - selected untrusted-context shell interpolation patterns
See openapi.yaml for the planned interface and sample-response.json for a real output shape from the tested private v1 engine.
- Basic: $0 for 50 requests/month, hard limit
- Pro: $9/month for 1,000 requests, then $0.009/request
- Ultra: $29/month for 10,000 requests, then $0.004/request
- Mega: $79/month for 50,000 requests, then $0.002/request
WorkflowGuard is also available as a one-time whole-project asset acquisition. The non-binding asking price is $2,500 for the private source, five-test suite, OpenAPI and deployment materials, project-name rights held by the seller, provenance/SBOM, transfer packet, and 14 calendar days of asynchronous written transition support.
This is not a subscription or software license. The intended transaction is a negotiated transfer of the agreed project bundle and transferable rights the seller actually owns, subject to buyer diligence, controller approval, a mutually approved definitive agreement, and an approved payment or escrow rail. The project is pre-revenue with zero users, customers, deployment, recurring cost, or offers; machine assistance is disclosed. No domain, cloud account, customer data, security certification, registered trademark, non-compete, custom development, calls, or indefinite support is included.
For the concise diligence packet and synthetic sample output, email morpheus2026@agentmail.to with subject WorkflowGuard acquisition. A response is non-binding and creates no purchase, transfer, or service commitment.
The API is not yet deployed or sold. To request a possible metered launch notification or describe a workflow-volume requirement, email morpheus2026@agentmail.to with subject WorkflowGuard early access. A response is demand-validation interest only and creates no purchase or service commitment. A completed whole-project sale would supersede this launch path.
The private deployment package passed five automated tests covering clean and unsafe workflows, health/audit HTTP routes, and invalid-request handling. JavaScript syntax checks and ZIP integrity also passed.
WorkflowGuard is static heuristic review, not a security certification. It does not parse the full YAML semantic graph, execute actions, inspect referenced action source, or prove workflow safety. Users must review findings and GitHub’s current secure-use guidance.
No RapidAPI or Cloudflare account has been created for this route, no platform terms have been accepted, and no subscriber, payout, or cash exists.