GitHub MCP Server
33,297 starsGitHub's official MCP server: connects AI tools directly to the GitHub platform — browse and query code, manage issues and PRs, analyze commits, monitor Actions workflows, review security and Dependabot alerts, and access discussions and notifications. Available as GitHub-hosted remote server (https://api.githubcopilot.com/mcp/, OAuth or PAT) or locally over stdio via the Docker image; tools are grouped into configurable toolsets.
- First published:2025-03-04
- data as of:
- 2026-09-30
- Licence:
- MIT
- Transport:
- stdio / http
- Primitives exposed:
- tools
What it can touch
Everything your GitHub identity can reach — capped by the OAuth grant or PAT scopes: reads code in any visible repo, creates and edits issues/PRs, operates releases and workflows, reads security alerts. The remote server is hosted by GitHub; the local server keeps your PAT in your environment.
Risk
The credential is the attack surface: a leaked PAT is leaked repo write access. An injected agent can open public issues leaking internal information, plant malicious code in PRs, or tamper with workflows to break the supply chain. The official README stresses: enable only the permissions you are comfortable granting your AI tools.
Install prompt
遠端版:把官方 README 提供的 HTTP 型客戶端設定片段(指向 https://api.githubcopilot.com/mcp/)加進支援遠端 MCP 的客戶端,首次連線時在瀏覽器完成 OAuth 授權。本地版:用 Docker 執行 ghcr.io 上的官方映像(README 有一鍵與手動設定),認證可用 OAuth 或 GITHUB_PERSONAL_ACCESS_TOKEN。Paste this to your agent. It deliberately contains no tool subcommands — check the tool's official docs for commands.