# GET /github/action: $0.005 per call

Is this GitHub Action safe for your workflow? Pass what follows uses: (e.g. tj-actions/changed-files@v45). Checks known advisories and compromises (OSV), SHA vs tag vs branch pinning, deprecated Node runtimes, unpinned Docker images and nested actions in action.yml, publisher and repository health. Verdict, score and fixes.

- **Price:** $0.005 in USDC, the same on Base, Solana, Polygon, Arbitrum. Failed calls are never charged.
- **Free trial:** yes, 20 free calls a day from Claude, Cursor or any MCP client ([set-up](/mcp/setup)).
- **Tier:** live
- **Answers cached for:** 1 hour(s)
- **Data sources:** OSV.dev GitHub Actions advisories (free); raw.githubusercontent.com (free); GitHub REST / ungh.cc (free)
- **Lane:** AI coding agents ([OpenAPI](/openapi/coding.json))
- **Live health:** [status page](/status)

## Free sample

See an answer for the demo input first, free (no payment, 10 a minute): [https://aayatai.com/sample/github-action](/sample/github-action). It is a stored real answer when we have one, otherwise an example marked `"kind": "illustrative"`.

```bash
curl "https://aayatai.com/sample/github-action"
```

## 1. See the price (free)

Call it without paying: you get `402 Payment Required` and a `PAYMENT-REQUIRED` header with the exact price and where to pay.

```bash
curl -i "https://aayatai.com/github/action?uses=tj-actions%2Fchanged-files%40v45.0.7"
```

## 2. Pay and call (TypeScript)

```bash
npm install @x402/fetch @x402/evm viem
```

```ts
import { wrapFetchWithPaymentFromConfig } from "@x402/fetch";
import { ExactEvmScheme } from "@x402/evm";
import { privateKeyToAccount } from "viem/accounts";

// A wallet used only by your agent, holding a little USDC on Base.
const account = privateKeyToAccount(process.env.WALLET_PRIVATE_KEY as `0x${string}`);
const pay = wrapFetchWithPaymentFromConfig(fetch, {
  schemes: [{ network: "eip155:8453", client: new ExactEvmScheme(account) }],
});

const res = await pay("https://aayatai.com/github/action?uses=tj-actions%2Fchanged-files%40v45.0.7");
console.log(await res.json());
```

## 3. Or as an MCP tool

```ts
// MCP server: https://aayatai.com/mcp (Streamable HTTP). With the x402 MCP client (see /start):
const result = await client.callTool("github-action", {"uses":"tj-actions/changed-files@v45.0.7"});
```

## Inputs

- `uses` **(required)** (string): The action reference, e.g. actions/checkout@v4 or owner/repo/sub@<40-char sha>.

Bad inputs are rejected with HTTP 400 before any payment is asked for.

## Example answer

```json
{
  "action": "tj-actions/changed-files",
  "ref": "v45.0.7",
  "pin": "version-tag",
  "publisher": "third-party",
  "verdict": "avoid",
  "score": 30,
  "flags": [
    {
      "level": "danger",
      "code": "vulnerable",
      "message": "1 advisory(ies) affect v45.0.7: tj-actions/changed-files has a malicious commit. Upgrade to 46.0.1."
    }
  ],
  "advisories": [
    {
      "id": "GHSA-mrrh-fwg8-r2c3",
      "aliases": [
        "CVE-2025-30066"
      ],
      "summary": "tj-actions/changed-files has a malicious commit",
      "severity": "high",
      "fixedIn": [
        "46.0.1"
      ],
      "published": "2025-03-15T00:00:00Z",
      "url": "https://osv.dev/vulnerability/GHSA-mrrh-fwg8-r2c3",
      "affectsThisRef": "yes"
    }
  ],
  "runtime": {
    "using": "composite",
    "image": null,
    "nestedUses": [],
    "actionYml": "https://raw.githubusercontent.com/tj-actions/changed-files/v45.0.7/action.yml"
  },
  "repository": {
    "url": "https://github.com/tj-actions/changed-files",
    "verdict": "healthy",
    "stars": 2600,
    "lastPushAt": "2026-09-20T00:00:00Z",
    "archived": false,
    "latestRelease": {
      "tag": "v47.0.0",
      "publishedAt": "2026-09-01T00:00:00Z"
    }
  },
  "sources": [
    "OSV.dev (GitHub Actions advisories)",
    "action.yml via raw.githubusercontent.com",
    "GitHub REST"
  ],
  "checkedAt": "2026-09-28T12:00:00.000Z"
}
```

## Related

- [GET /docs/find](/services/docs-find) ($0.003): Find the AI-ready docs for any library or API: checks the project's docs site (from its npm, PyPI, crates or Go metadata) or any company domain (docs., develope
- [GET /docs/lib](/services/docs-lib) ($0.005): Up-to-date docs for any npm, PyPI, crates or Go library, trimmed for a coding agent's context: finds the project's own llms.txt and docs pages (or the latest re
- [POST /docs/answer](/services/docs-answer) ($0.02): Ask a coding question about any npm, PyPI, crates or Go library and get an answer written only from its current docs (project llms.txt, docs pages or latest REA
- [GET /openapi](/services/openapi) ($0.005): Understand any public API fast: give its OpenAPI/Swagger spec URL, its docs or base URL, or a name from the APIs.guru directory (?api=stripe.com); we find the s
- [GET /library/research](/services/library-research) ($0.10): Premium research report on a library or API for coding agents: reads its current docs for your goal, checks version, safety and repository health, gathers what 
- [GET /package/check](/services/package-check) ($0.005): Should a coding agent install this package?
- [GET /dependency/verdict](/services/dependency-verdict) ($0.03): "Should I use this dependency?" in one call for npm, PyPI, crates or Go: full package safety check (vulnerabilities, malware, typosquats, deprecation, licence, 
- [GET /dependency/report](/services/dependency-report) ($0.08): Premium "should I use this dependency?" report: package safety (vulnerabilities, malware, typosquats, deprecation), GitHub repository health, licence compatibil

New here? [Getting started in 60 seconds](/start). All services: [Aayat AI](/).