REPOSITORY EVIDENCE / INDEXABLE REPORT

github/github-mcp-server — MCP & Agent Security Evidence Report

MCP host configuration, repository automation and dependency evidence were observed in this selected bounded review. Evidence observations are review signals, not a safe/unsafe verdict.

Is github/github-mcp-server safe to run?

ShadowMCP does not issue a safe/unsafe verdict. This report records bounded evidence tied to a specific commit so reviewers can identify what deserves inspection before use.

Scan identity

Report schemashadowmcp.repo-evidence.v9
Scannershadowmcp.web-repo-scan.v22 semantics
Scan completed2026-09-25T08:30:00.000Z
Repository branchmain
Scanned commit85598ba6e1256f7ebf4867b95d63b833c4549264
Indexation gateIndexable quality gate passed.

Evidence summary

Review priority
Priority review

This is a triage priority, not a repository risk rating.

This is GitHub's official MCP Server. The bounded review observed documented remote/local MCP host configuration, GitHub repository automation and an explicit Model Context Protocol Go SDK dependency.

Evidence categories

MCP configuration

Found

Selected configuration evidence was observed. This does not establish how any user's client is configured.

  • README.mdremote MCP HTTP endpoint and host configuration examples, including PAT authentication

Shell / command execution

Not established

No shell/command execution claim is made from the selected bounded evidence.

CI/CD automation

Found

Repository-level GitHub automation is present in the selected scope.

  • .github/GitHub repository automation directory observed

Supply-chain / dependencies

Found

Selected dependency declarations were observed; this is not a complete dependency audit.

  • go.modgithub.com/modelcontextprotocol/go-sdk v1.7.0 and GitHub/API dependencies declared

Scope and limitations

Scan mode: BOUNDED_ROOT_AND_SELECTED_DEPTH1_PLUS_TARGETED_SEARCH. General recursive crawl: NO.

  • Public, selected and bounded repository evidence only.
  • FOUND means evidence observed, not risk or malicious behavior proven.
  • Evidence was reviewed against immutable commit 85598ba6e1256f7ebf4867b95d63b833c4549264.
  • No repository clone or target-code execution.
  • No secret/token values are included.
  • No CVE or package-reputation lookup.
  • No numeric security score and no safe/unsafe verdict.

Repository context

Trust/community metadata is descriptive context only; it is not a security guarantee.

Repository age / activitycreated 2025-03-04 · active in September 2026
Community signalsstars 33,187 · forks 5,047 · open issues 343
OwnershipOrganization · github
LicenseMIT
Repository statearchived NO · fork NO · default branch main

Continue the review