Scan identity
Evidence summary
This is GitHub's official MCP Server. The bounded review observed documented remote/local MCP host configuration, GitHub repository automation and an explicit Model Context Protocol Go SDK dependency.
Evidence categories
MCP configuration
FoundSelected configuration evidence was observed. This does not establish how any user's client is configured.
README.mdremote MCP HTTP endpoint and host configuration examples, including PAT authentication
Shell / command execution
Not establishedNo shell/command execution claim is made from the selected bounded evidence.
CI/CD automation
FoundRepository-level GitHub automation is present in the selected scope.
.github/GitHub repository automation directory observed
Supply-chain / dependencies
FoundSelected dependency declarations were observed; this is not a complete dependency audit.
go.modgithub.com/modelcontextprotocol/go-sdk v1.7.0 and GitHub/API dependencies declared
Scope and limitations
Scan mode: BOUNDED_ROOT_AND_SELECTED_DEPTH1_PLUS_TARGETED_SEARCH. General recursive crawl: NO.
- Public, selected and bounded repository evidence only.
- FOUND means evidence observed, not risk or malicious behavior proven.
- Evidence was reviewed against immutable commit 85598ba6e1256f7ebf4867b95d63b833c4549264.
- No repository clone or target-code execution.
- No secret/token values are included.
- No CVE or package-reputation lookup.
- No numeric security score and no safe/unsafe verdict.
Repository context
Trust/community metadata is descriptive context only; it is not a security guarantee.