RRepoGEO

REPOGEO REPORT · LITE

step-security/harden-runner

Default branch main · commit 9af89fc7 · scanned 6/27/2026, 2:01:49 AM

GitHub: 1,207 stars · 106 forks

Scan history for this repo

Score trend below includes all ready runs (older left, newer right; scroll horizontally if needed). The table is collapsed by default—expand for newest-first rows, 10 per page.

Score trend (left → right: older → newer)

3 ready scans. Expand the table below for newest-first rows (10 per page, paginated).

AI VISIBILITY SCORE
33 /100
Critical
Category recall
0 / 2
Not recommended in any query
Rule findings
2 pass · 0 warn · 0 fail
Objective metadata checks
AI knows your name
2 / 3
Direct prompts that named your repo
HOW TO READ THIS REPORT

Action plan is what to do next — copy-pasteable changes prioritized by impact. Category visibility is the real GEO test: when a user asks an AI a brand-free question that should surface step-security/harden-runner, does the AI actually recommend you — or your competitors? Objective checks verify the metadata signals AI engines weight first. Self-mention check detects whether AI even knows you exist by name.

Action plan — copy-paste fixes

3 prioritized changes generated by gemini-2.5-flash. Mark items done after you ship the fix.

OVERALL DIRECTION
  • highreadme#1
    Reposition the README's opening paragraph to clearly state its unique category

    Why:

    CURRENT
    Corporate laptops and production servers typically have robust security monitoring in place to reduce risk and meet compliance requirements. However, CI/CD runners, which handle sensitive information like secrets for cloud environments and create production builds, often lack such security measures. This oversight has led to significant supply chain attacks, including the SolarWinds and Codecov breaches. Traditional security monitoring and EDR solutions are ineffective for CI/CD runners due to their ephemeral nature. These tools also lack the necessary context to correlate events with specific workflow runs in a CI/CD environment. StepSecurity Harden-Runner addresses this gap by providing security monitoring tailored for CI/CD runners, with support for Linux, Windows, and macOS runners. This approach brings CI/CD runners under the same level of security scrutiny as other critical systems, addressing a significant gap in the software supply chain.
    COPY-PASTE FIX
    StepSecurity Harden-Runner is a specialized CI/CD security agent that functions as an EDR (Endpoint Detection and Response) solution specifically designed for GitHub Actions runners. Unlike traditional EDRs or general supply chain security tools, Harden-Runner provides real-time monitoring of network egress, file integrity, and process activity on ephemeral runners, detecting threats tailored to the CI/CD environment.
  • mediumreadme#2
    Add a 'Why Harden-Runner?' or 'Comparison' section to the README

    Why:

    COPY-PASTE FIX
    Add a new section titled 'Why Harden-Runner?' or 'Comparison to Other Tools' that explicitly contrasts its capabilities with general vulnerability scanners (e.g., Trivy), runtime security tools (e.g., Falco), or broad EDR platforms, emphasizing its unique focus on GitHub Actions runner-specific EDR. For example: 'While tools like Trivy scan for vulnerabilities and Falco monitors general runtime activity, Harden-Runner provides an EDR-like capability *within* your GitHub Actions runners, offering granular, real-time threat detection and policy enforcement specifically for CI/CD workflows.'
  • lowtopics#3
    Add more specific topics to reinforce the unique category

    Why:

    CURRENT
    actions, egress-filtering, github-actions, hardening, network-security, runners, runtime-security, security-hardening, supply-chain-security
    COPY-PASTE FIX
    Add `ci-cd-security-agent` and `github-actions-edr` to the existing topics.

Category GEO backends resolved for this scan: google/gemini-2.5-flash, deepseek/deepseek-v4-flash

Category visibility — the real GEO test

Brand-free queries asked to google/gemini-2.5-flash. Did AI recommend you, or someone else?

Same questions for every model — switch tabs to compare answers and rankings.

Recall
0 / 2
0% of queries surface step-security/harden-runner
Avg rank
Lower is better. #1 = top recommendation.
Share of voice
0%
Of all named tools, what % are you?
Top rival
aquasecurity/trivy
Recommended in 2 of 2 queries
COMPETITOR LEADERBOARD
  1. aquasecurity/trivy · recommended 2×
  2. falcosecurity/falco · recommended 2×
  3. GitHub Advanced Security (GHAS) · recommended 1×
  4. CrowdStrike Falcon · recommended 1×
  5. SentinelOne Singularity · recommended 1×
  • CATEGORY QUERY
    How to implement real-time security monitoring and threat detection for GitHub Actions runners?
    you: not recommended
    AI recommended (in order):
    1. GitHub Advanced Security (GHAS)
    2. CrowdStrike Falcon
    3. SentinelOne Singularity
    4. Microsoft Defender for Endpoint
    5. Palo Alto Networks Cortex XDR
    6. Aqua Security Trivy (aquasecurity/trivy)
    7. Wiz
    8. Lacework Polygraph
    9. Palo Alto Networks Prisma Cloud
    10. Osquery (osquery/osquery)
    11. Falco (falcosecurity/falco)
    12. Splunk Enterprise Security
    13. Elastic Security (ELK Stack)
    14. Datadog Security Monitoring
    15. Sumo Logic Cloud SIEM

    AI recommended 15 alternatives but never named step-security/harden-runner. This is the gap to close.

    Show full AI answer
  • CATEGORY QUERY
    What tools can harden CI/CD pipelines and prevent supply chain attacks on ephemeral runners?
    you: not recommended
    AI recommended (in order):
    1. Sigstore (sigstore/sigstore)
    2. Open Policy Agent (open-policy-agent/opa)
    3. Gatekeeper (open-policy-agent/gatekeeper)
    4. Trivy (aquasecurity/trivy)
    5. Falco (falcosecurity/falco)
    6. Distroless Images (GoogleContainerTools/distroless)
    7. in-toto (in-toto/in-toto)
    8. GitHub Actions OIDC
    9. GitLab CI/CD OIDC

    AI recommended 9 alternatives but never named step-security/harden-runner. This is the gap to close.

    Show full AI answer

Objective checks

Rule-based audits of metadata signals AI engines weight most.

  • Metadata completeness
    pass

  • README presence
    pass

Self-mention check

Does AI even know your repo exists when asked about it directly?

  • Compared to common alternatives in this category, what is the core differentiator of step-security/harden-runner?
    pass
    AI did not name step-security/harden-runner — likely talking about a different project

    AI answers can be confidently wrong. Read for accuracy: does it match your actual tech stack, audience, and differentiator?

  • If a team adopts step-security/harden-runner in production, what risks or prerequisites should they evaluate first?
    pass
    AI named step-security/harden-runner explicitly

    AI answers can be confidently wrong. Read for accuracy: does it match your actual tech stack, audience, and differentiator?

  • In one sentence, what problem does the repo step-security/harden-runner solve, and who is the primary audience?
    pass
    AI named step-security/harden-runner explicitly

    AI answers can be confidently wrong. Read for accuracy: does it match your actual tech stack, audience, and differentiator?

Embed your GEO score

Drop this badge into the README of step-security/harden-runner. It auto-updates whenever the report is rescanned and links back to the latest report — easy public proof that you care about AI discoverability.

RepoGEO badge previewLive preview
MARKDOWN (README)
[![RepoGEO](https://repogeo.com/badge/step-security/harden-runner.svg)](https://repogeo.com/en/r/step-security/harden-runner)
HTML
<a href="https://repogeo.com/en/r/step-security/harden-runner"><img src="https://repogeo.com/badge/step-security/harden-runner.svg" alt="RepoGEO" /></a>
Pro

Subscribe to Pro for deep diagnoses

step-security/harden-runner — Lite scans stay free; this card itemizes Pro deep limits vs Lite.

  • Deep reports10 / month
  • Brand-free category queries5 vs 2 in Lite
  • Prioritized action items8 vs 3 in Lite