A GitHub required check for AI-agent pull requests

Add avouro-com/scopebond/packages/github-action@v1 as a required status check. It evaluates a pull request against your policy in your own Actions runner and fails an out-of-policy agent PR before it can merge, names the agent's bot account (Copilot, Codex, Claude and others), and signs a record you can verify offline. A human pull request that isn't from an agent emits none.

1. Add the workflow

Add the Action to a workflow and make the job a required status check on your protected branch (Settings → Branches).

# .github/workflows/scopebond.yml
name: Scopebond
on: pull_request
jobs:
  policy:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: avouro-com/scopebond/packages/github-action@v1
        with:
          policy: .scopebond/policy.json

2. What it produces

The check passes or fails per pull request version; with a signing key configured (SCOPEBOND_ATTESTER_KEY) it produces a signed record naming the agent's bot account, verifiable offline with npx @scopebond/verify@latest.

What this does not do

The Action checks whether the pull request may merge. It does not check what the agent does on a developer's machine; use the local hook for that. The signed record proves the check's decision on that version of the pull request, not runtime behavior or compliance.

Alternatives

FAQ

Does it block a human's pull request?

It evaluates against your policy; a pull request that is not from a configured agent bot produces no Scopebond record, and you decide which authors the check applies to.

Where does the check run?

In your own GitHub Actions runner, against your policy file — nothing leaves your CI, and the signing key stays in your runner.

Last verified 2026-09-22. Commands are covered by the public repo's tests (packages/github-action/test).