08:43
2026-07-19
dev.to
developer-tools
Two ways to reuse a privileged CI token (and my rule only caught one)
A developer shipped a security rule for mcpscan, a static scanner for MCP configs and GitHub Actions workflows, that only caught half of a privileged CI token reuse vulnerability. The rule, MCP019 in β¦