Intake notes: audit deferred until it can be run properly. It’s a Go binary that ships via Docker or the GitHub-hosted remote, and a verdict here means actually booting one of those paths, not reading source alone. When vetted: compare the remote-hosted path against the local Docker path, count the (large) tool surface it injects, and exercise the read-only and toolset-scoping configuration.
github-mcp-server
• Not yet vettedGitHub's official MCP server: repos, issues, pull requests, and Actions through the GitHub API, hosted remotely or run locally in Docker.
In the intake queue. Listed with facts only; no verdict until a human runs it.
by GitHub MCP server DevOps
Shipped today passing liveness · checked Jul 28, 2026
Commit activity · last 52 weeks
Stars32k
LanguageGo
LicenseMIT
Open issues352
Pricingfree
ListedJul 11, 2026
Facts pulled from the source repo and refreshed nightly. Stars are a data point, not our ranking. We don't order by popularity.
Runs in
| Harness | Support | Notes |
|---|---|---|
| Claude Code | untested | — |
| Any MCP client | untested | — |
Support levels reflect what we actually ran, not what the README claims. untested means exactly that.
What a vet will check
- Whether it can act or write when told not to (read-only and scope enforcement)
- What it injects per session: token cost and the size of the tool surface
- Where your data goes: any call that leaves your machine, disclosed or not
No verdict is published until a human installs it, runs it, and audits what it injects. How vetting works →