{"owner":"step-security","github":"https://github.com/step-security","claimed":false,"inventory":[],"indexed":[{"repo":"step-security/harden-runner","github":"https://github.com/step-security/harden-runner","description":"Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-time.","language":"TypeScript","stars":1250,"topics":["github-actions","actions","supply-chain-security","hardening","security-hardening","runners","egress-filtering","network-security","runtime-security"],"license":"Apache-2.0","category":"deployment-docker-iac"},{"repo":"step-security/secure-repo","github":"https://github.com/step-security/secure-repo","description":"Orchestrate GitHub Actions Security","language":"Go","stars":329,"topics":["security","github-actions","workflow","actions","github","golang","supply-chain-security","security-tools"],"license":"AGPL-3.0","category":"workflow-automation"},{"repo":"step-security/wait-for-secrets","github":"https://github.com/step-security/wait-for-secrets","description":"Publish from GitHub Actions using multi-factor authentication","language":"TypeScript","stars":299,"topics":["action","actions","github-actions","mfa","security"],"license":"Apache-2.0","category":"security-tools"},{"repo":"step-security/dev-machine-guard","github":"https://github.com/step-security/dev-machine-guard","description":"Scan your dev machine for AI agents, MCP servers, IDE extensions, and suspicious packages - in seconds.","language":"Go","stars":170,"topics":["ai-agents","endpoint-security","mcp-servers","supply-chain-security","vscode-extensions"],"license":"Apache-2.0","category":"mcp-servers"},{"repo":"step-security/agent","github":"https://github.com/step-security/agent","description":"Purpose-built security agent for hosted runners","language":"Go","stars":48,"topics":["security","github-actions"],"license":"Apache-2.0","category":"security-tools"}],"how_to_buy":"GET /r/step-security/<repo> (Accept: application/json) for any listed repo here: tree, README, price and the checkout to pay (x402; rehearse first at its test twin, simulated money). Repos under 'indexed' are free: clone them from GitHub."}