github_check_pat_usage
Classic vs fine-grained PAT usage
How to use it
github_check_pat_usage is exposed by the Github Security MCP MCP server. Add the server to your MCP client (Claude Desktop, Cursor, Windsurf and others), and the github_check_pat_usage tool becomes available to the model automatically. See the full listing for setup details and every tool this server provides.
Install Github Security MCP
claude mcp add github-security -- bun run /path/to/github-security-mcp/src/index.tsOther tools in Github Security MCP (38)
Full markdown or JSON audit report
Aggregate findings by category, severity, status
GitHub App permission scope review
External collaborator access audit
Dependabot security updates configuration
Dependency graph enablement
OAuth credential authorizations, GitHub App installation permissions
Suspicious audit log activity (Enterprise)
Outside collaborators, stale member detection
2FA enforcement, default repo visibility, member creation privileges
SSO/SAML configuration via GraphQL
Insecure webhook URLs (HTTP, no secret)
Push protection bypass tracking
Branch protection rules on default branch
CodeQL / code scanning enabled, open alerts
CODEOWNERS file presence and enforcement
Dependabot enabled, critical alert triage
Deploy key permissions (read-only vs read-write)
Secret scanning and push protection enablement
SECURITY.md, private vulnerability reporting, fork restrictions
Insecure repo-level webhook URLs
SBOM generation capability
Custom secret pattern configuration
Coverage gaps and unresolved alerts
Environment, repo, and org-level secret scoping
Team permission levels across repos
Known vulnerabilities, critical unfixed > 90 days
Missing environment protection rules
Script injection via ${{ github.event. }} in run: blocks
OIDC subject claim customization
GITHUBTOKEN default permission scope
Unpinned third-party actions (tag vs SHA)
pullrequesttarget + checkout pattern (critical)
Self-hosted runner exposure
Secret exfiltration patterns in workflows
Browse all 45 checks, filter by category/severity
List all repos in an org with security metadata
Execute all checks for an org/repo