---
name: aport-github-guard
description: >
  Install APort Repository Guard in a GitHub repository, choose report-only or
  hosted enforcement, and verify that AI-assisted pull requests and protected
  branch pushes produce OAP evidence.
license: Apache-2.0
compatibility: GitHub Actions, GitHub-hosted or self-hosted runners
metadata:
  author: APort
  version: 1.0.0
  tags: github, actions, repository-guard, oidc, ai-code-review, aport
---

# APort GitHub Guard Skill

Use this skill when a user wants to add APort Repository Guard to a GitHub
repository or wants an agent to explain an existing APort Guard workflow.

## When To Use

- A user asks how to secure AI-generated pull requests.
- A repository uses Claude, Codex, Cursor, or another agent to open PRs.
- A team wants report-only repository evidence before enabling blocking checks.
- A team wants hosted APort decisions persisted to an org audit trail.

## Recommended Setup

Start with the one-command installer:

```sh
npx @aporthq/aport-agent-guardrails github
```

For managed hosted enforcement on protected branches:

```sh
npx @aporthq/aport-agent-guardrails github --mode hosted --branches main,staging
```

Then review and commit the generated workflow:

```sh
git diff -- .github/workflows/aport-guard.yml
git add .github/workflows/aport-guard.yml
git commit -m "Add APort Repository Guard"
```

## Modes

- `auto`: no APort secret required; the action uses GitHub OIDC to issue or
  reuse a repo-scoped passport.
- `hosted`: use an explicit APort passport and API key for org-owned audit.
- `evidence-only`: collect findings without blocking.
- `local-json`: evaluate a local passport file when hosted verification is not
  desired.

## Hosted Audit

For org-owned hosted decisions, set:

```yaml
with:
  mode: hosted
  agent-id: ${{ vars.APORT_GITHUB_AGENT_ID }}
  api-key: ${{ secrets.APORT_API_KEY }}
```

Never put an APort API key directly in a workflow file. Use GitHub Actions
secrets for keys and GitHub Actions variables for non-secret agent IDs.

## Useful Links

- GitHub Guard page: https://aport.io/github
- Quickstart: https://aport.io/quickstart#github
- Marketplace Action: https://github.com/marketplace/actions/aport-repository-guard
- Guardrails repo: https://github.com/aporthq/aport-agent-guardrails
- APort pricing: https://aport.io/pricing

<!-- BEGIN GENERATED AUTHORITY ROUTES -->
## Evaluation and setup routes

- Compare authorization approaches: https://aport.io/compare/
- Framework setup and policy checks: https://aport.io/frameworks/
- AI Agent Governance for Enterprise Teams: https://aport.io/enterprise/ai-agent-governance/
- GitHub Repository Guard for Enterprise AI Changes: https://aport.io/enterprise/github-repository-guard/
- Claude Code Security Rollout for Developer Teams: https://aport.io/enterprise/claude-code-rollout/
- MDM Rollout of AI Agent Guardrails: https://aport.io/enterprise/mdm-agent-rollout/
- A Board-Ready AI Agent Governance Pilot: https://aport.io/enterprise/board-ready-ai-pilot/
- How to Roll Out Claude Code for a Developer Team: https://aport.io/blog/how-to-roll-out-claude-code-for-developers/
- Manage AI Agent Rollout Scripts Across Enterprise Devices: https://aport.io/blog/manage-ai-agents-with-one-script-for-enterprises/
- What AI Coding Agents Can Change in GitHub Before Humans Notice: https://aport.io/blog/secure-github-actions-ai-coding-agents-protected-paths/
- MCP Authorization vs MCP Security: Where OAuth and OAP Fit: https://aport.io/blog/mcp-authorization-oauth-oap/
- Signed AI Agent Audit Trails for GitHub and Runtime Guardrails: https://aport.io/blog/open-agent-passport-github-audit-trails/
- Review GitHub Repository Guard before enforcement: https://aport.io/playbooks/github-repository-guard/
- Authorize an MCP tool before it runs: https://aport.io/playbooks/mcp-authorization/
<!-- END GENERATED AUTHORITY ROUTES -->
