MCPVault
Github Security MCP logo

Github Security MCP

Unclaimed

by badchars

GitHub security posture analysis for AI agents — 39 MCP tools, 45 checks across org, repos, Actions, secrets, supply chain, and access control

access-controlai-agentbranch-protectionbuncodeqldependabotdevsecopsgithub-actionsgithub-apigithub-securityiammcpmcp-servermodel-context-protocolsastsecret-scanningsecurity-auditsupply-chain-securitytypescriptvulnerability-detection

Install

$claude mcp add github-security -- bun run /path/to/github-security-mcp/src/index.ts

Unclaimed listing

Is this your MCP server?

This listing was auto-indexed from the public record. Claim it to edit the page, set compatibility and unlock growth tools. Takes under two minutes.

Claim this server

Tools (39)

github_audit_report

Full markdown or JSON audit report

github_audit_summary

Aggregate findings by category, severity, status

github_check_app_permissions

GitHub App permission scope review

github_check_collaborators

External collaborator access audit

github_check_dependabot_updates

Dependabot security updates configuration

github_check_dependency_graph

Dependency graph enablement

github_check_org_apps

OAuth credential authorizations, GitHub App installation permissions

github_check_org_audit_log

Suspicious audit log activity (Enterprise)

github_check_org_members

Outside collaborators, stale member detection

github_check_org_security

2FA enforcement, default repo visibility, member creation privileges

github_check_org_sso

SSO/SAML configuration via GraphQL

github_check_org_webhooks

Insecure webhook URLs (HTTP, no secret)

github_check_pat_usage

Classic vs fine-grained PAT usage

github_check_push_protection

Push protection bypass tracking

github_check_repo_branch_protection

Branch protection rules on default branch

github_check_repo_code_scanning

CodeQL / code scanning enabled, open alerts

github_check_repo_codeowners

CODEOWNERS file presence and enforcement

github_check_repo_dependabot

Dependabot enabled, critical alert triage

github_check_repo_deploy_keys

Deploy key permissions (read-only vs read-write)

github_check_repo_secrets

Secret scanning and push protection enablement

github_check_repo_settings

SECURITY.md, private vulnerability reporting, fork restrictions

github_check_repo_webhooks

Insecure repo-level webhook URLs

github_check_sbom

SBOM generation capability

github_check_secret_patterns

Custom secret pattern configuration

github_check_secret_scanning

Coverage gaps and unresolved alerts

github_check_secret_scoping

Environment, repo, and org-level secret scoping

github_check_team_permissions

Team permission levels across repos

github_check_vulnerabilities

Known vulnerabilities, critical unfixed > 90 days

github_check_workflow_environments

Missing environment protection rules

github_check_workflow_injection

Script injection via ${{ github.event. }} in run: blocks

github_check_workflow_oidc

OIDC subject claim customization

github_check_workflow_permissions

GITHUBTOKEN default permission scope

github_check_workflow_pinning

Unpinned third-party actions (tag vs SHA)

github_check_workflow_pr_target

pullrequesttarget + checkout pattern (critical)

github_check_workflow_runners

Self-hosted runner exposure

github_check_workflow_secrets

Secret exfiltration patterns in workflows

github_list_checks

Browse all 45 checks, filter by category/severity

github_list_org_repos

List all repos in an org with security metadata

github_run_all

Execute all checks for an org/repo