diff --git a/.github/workflows/scan.yml b/.github/workflows/scan.yml index 07bd736..60808b1 100644 --- a/.github/workflows/scan.yml +++ b/.github/workflows/scan.yml @@ -27,13 +27,7 @@ jobs: run: npx @anthropic-ai/mcpb pack - name: Run MTF scanner - run: | - if pip install mpak-scanner 2>/dev/null; then - mpak-scanner scan *.mcpb --json > scan-results.json - else - echo "mpak-scanner not yet available — skipping client-side scan" - echo '{"findings": []}' > scan-results.json - fi + run: uvx mpak-scanner scan *.mcpb --json > scan-results.json - name: Check for critical/high findings run: |