BackBond

AGENT SCAN / GUIDE

Put the check in CI.

The existing Action runs the pinned static profile against a manifest committed to a repository you control.

Pin the workflow

Use the integration page to download the workflow. It pins BackBond/agent-scan@v0.6.2 and the checkout action by commit. Change the manifest path, review the permissions, and commit it to your repository.

Run it on pull requests and pushes that change the manifest. Require the check before merging only if that matches your repository policy.

Read the boundary

A passing run means the committed file at that commit produced no_blocking_finding under the pinned profile. It is not a certification, runtime verification, insurance decision, or proof that the deployed server matches the file.