A GitHub required check for AI-agent pull requests
Add avouro-com/scopebond/packages/github-action@v1 as a required status check. It evaluates a pull request against your policy in your own Actions runner and fails an out-of-policy agent PR before it can merge, names the agent's bot account (Copilot, Codex, Claude and others), and signs a record you can verify offline. A human pull request that isn't from an agent emits none.
1. Add the workflow
Add the Action to a workflow and make the job a required status check on your protected branch (Settings → Branches).
# .github/workflows/scopebond.yml
name: Scopebond
on: pull_request
jobs:
policy:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: avouro-com/scopebond/packages/github-action@v1
with:
policy: .scopebond/policy.json
2. What it produces
The check passes or fails per pull request version; with a signing key configured (SCOPEBOND_ATTESTER_KEY) it produces a signed record naming the agent's bot account, verifiable offline with npx @scopebond/verify@latest.
What this does not do
The Action checks whether the pull request may merge. It does not check what the agent does on a developer's machine; use the local hook for that. The signed record proves the check's decision on that version of the pull request, not runtime behavior or compliance.
Alternatives
- GitHub branch protection and CODEOWNERS — native required reviews; Scopebond adds a policy check specific to agent PRs and a signed record.
- Endor Labs and similar CI scanners — code/security findings in CI; Scopebond gates on your agent policy and signs the decision.
FAQ
Does it block a human's pull request?
It evaluates against your policy; a pull request that is not from a configured agent bot produces no Scopebond record, and you decide which authors the check applies to.
Where does the check run?
In your own GitHub Actions runner, against your policy file — nothing leaves your CI, and the signing key stays in your runner.
Last verified 2026-09-22. Commands are covered by the public repo's tests (packages/github-action/test).