# GitHub MCP server

Agent View of the PolicyLayer registry record for GitHub: identity, probed posture, risk grade, and all 86 tools classified. HTML page: https://policylayer.com/tools/github

## Facts

- Server id: `oci:ghcr.io/github/github-mcp-server:1.3.0`
- Ref (npm): `@github/github-mcp-server`
- Ref (oci): `oci:ghcr.io/github/github-mcp-server:1.1.2`
- Ref (npm): `@modelcontextprotocol/server-github`
- Ref (repo): `github/github-mcp-server`
- Ref (remote): `https://api.githubcopilot.com/mcp/`
- Ref (smithery): `github`
- Ref (repo): `opendata-kr/.github`
- Ref (repo): `en/search-github`
- Ref (repo): `altion-labs/.github`
- Homepage: https://github.com/github/github-mcp-server
- Registry record: grade D, identity verified
- Lifecycle: active
- Auth posture: gated
- Rate-limited: no
- Tools: 86 (84 with introspected schema)
- Tool categories present: Destructive, Execute, Read, Write
- Context-window cost: 14406 tokens per request — https://policylayer.com/token-cost/github
- Tags: github, admin, automation
- Record last modified: 2026-06-12T18:29:43.783Z

## Tools (86)

| Tool | Category | Risk | Record |
| --- | --- | --- | --- |
| `delete_file` | Destructive | Critical | https://policylayer.com/tools/github/delete-file.md |
| `projects_write` | Destructive | Critical | https://policylayer.com/tools/github/projects-write.md |
| `actions_run_trigger` | Execute | High | https://policylayer.com/tools/github/actions-run-trigger.md |
| `assign_copilot_to_issue` | Execute | High | https://policylayer.com/tools/github/assign-copilot-to-issue.md |
| `actions_get` | Read | Low | https://policylayer.com/tools/github/actions-get.md |
| `actions_list` | Read | Low | https://policylayer.com/tools/github/actions-list.md |
| `get_code_scanning_alert` | Read | Low | https://policylayer.com/tools/github/get-code-scanning-alert.md |
| `get_commit` | Read | Low | https://policylayer.com/tools/github/get-commit.md |
| `get_copilot_job_status` | Read | Low | https://policylayer.com/tools/github/get-copilot-job-status.md |
| `get_copilot_space` | Read | Low | https://policylayer.com/tools/github/get-copilot-space.md |
| `get_dependabot_alert` | Read | Low | https://policylayer.com/tools/github/get-dependabot-alert.md |
| `get_discussion` | Read | Low | https://policylayer.com/tools/github/get-discussion.md |
| `get_discussion_comments` | Read | Low | https://policylayer.com/tools/github/get-discussion-comments.md |
| `get_file_contents` | Read | Low | https://policylayer.com/tools/github/get-file-contents.md |
| `get_gist` | Read | Low | https://policylayer.com/tools/github/get-gist.md |
| `get_global_security_advisory` | Read | Low | https://policylayer.com/tools/github/get-global-security-advisory.md |
| `get_job_logs` | Read | Low | https://policylayer.com/tools/github/get-job-logs.md |
| `get_label` | Read | Low | https://policylayer.com/tools/github/get-label.md |
| `get_latest_release` | Read | Low | https://policylayer.com/tools/github/get-latest-release.md |
| `get_me` | Read | Low | https://policylayer.com/tools/github/get-me.md |
| `get_notification_details` | Read | Low | https://policylayer.com/tools/github/get-notification-details.md |
| `get_release_by_tag` | Read | Low | https://policylayer.com/tools/github/get-release-by-tag.md |
| `get_repository_tree` | Read | Low | https://policylayer.com/tools/github/get-repository-tree.md |
| `get_secret_scanning_alert` | Read | Low | https://policylayer.com/tools/github/get-secret-scanning-alert.md |
| `get_tag` | Read | Low | https://policylayer.com/tools/github/get-tag.md |
| `get_team_members` | Read | Low | https://policylayer.com/tools/github/get-team-members.md |
| `get_teams` | Read | Low | https://policylayer.com/tools/github/get-teams.md |
| `github_support_docs_search` | Read | Low | https://policylayer.com/tools/github/github-support-docs-search.md |
| `issue_read` | Read | Low | https://policylayer.com/tools/github/issue-read.md |
| `list_branches` | Read | Low | https://policylayer.com/tools/github/list-branches.md |
| `list_code_scanning_alerts` | Read | Low | https://policylayer.com/tools/github/list-code-scanning-alerts.md |
| `list_commits` | Read | Low | https://policylayer.com/tools/github/list-commits.md |
| `list_copilot_spaces` | Read | Low | https://policylayer.com/tools/github/list-copilot-spaces.md |
| `list_dependabot_alerts` | Read | Low | https://policylayer.com/tools/github/list-dependabot-alerts.md |
| `list_discussion_categories` | Read | Low | https://policylayer.com/tools/github/list-discussion-categories.md |
| `list_discussions` | Read | Low | https://policylayer.com/tools/github/list-discussions.md |
| `list_gists` | Read | Low | https://policylayer.com/tools/github/list-gists.md |
| `list_global_security_advisories` | Read | Low | https://policylayer.com/tools/github/list-global-security-advisories.md |
| `list_issue_types` | Read | Low | https://policylayer.com/tools/github/list-issue-types.md |
| `list_issues` | Read | Low | https://policylayer.com/tools/github/list-issues.md |
| `list_label` | Read | Low | https://policylayer.com/tools/github/list-label.md |
| `list_notifications` | Read | Low | https://policylayer.com/tools/github/list-notifications.md |
| `list_org_repository_security_advisories` | Read | Low | https://policylayer.com/tools/github/list-org-repository-security-advisories.md |
| `list_pull_requests` | Read | Low | https://policylayer.com/tools/github/list-pull-requests.md |
| `list_releases` | Read | Low | https://policylayer.com/tools/github/list-releases.md |
| `list_repository_security_advisories` | Read | Low | https://policylayer.com/tools/github/list-repository-security-advisories.md |
| `list_secret_scanning_alerts` | Read | Low | https://policylayer.com/tools/github/list-secret-scanning-alerts.md |
| `list_starred_repositories` | Read | Low | https://policylayer.com/tools/github/list-starred-repositories.md |
| `list_tags` | Read | Low | https://policylayer.com/tools/github/list-tags.md |
| `projects_get` | Read | Low | https://policylayer.com/tools/github/projects-get.md |
| `projects_list` | Read | Low | https://policylayer.com/tools/github/projects-list.md |
| `pull_request_read` | Read | Low | https://policylayer.com/tools/github/pull-request-read.md |
| `run_secret_scanning` | Read | Low | https://policylayer.com/tools/github/run-secret-scanning.md |
| `search_code` | Read | Low | https://policylayer.com/tools/github/search-code.md |
| `search_issues` | Read | Low | https://policylayer.com/tools/github/search-issues.md |
| `search_orgs` | Read | Low | https://policylayer.com/tools/github/search-orgs.md |
| `search_pull_requests` | Read | Low | https://policylayer.com/tools/github/search-pull-requests.md |
| `search_repositories` | Read | Low | https://policylayer.com/tools/github/search-repositories.md |
| `search_users` | Read | Low | https://policylayer.com/tools/github/search-users.md |
| `add_comment_to_pending_review` | Write | Medium | https://policylayer.com/tools/github/add-comment-to-pending-review.md |
| `add_issue_comment` | Write | Medium | https://policylayer.com/tools/github/add-issue-comment.md |
| `add_reply_to_pull_request_comment` | Write | Medium | https://policylayer.com/tools/github/add-reply-to-pull-request-comment.md |
| `create_branch` | Write | Medium | https://policylayer.com/tools/github/create-branch.md |
| `create_gist` | Write | Medium | https://policylayer.com/tools/github/create-gist.md |
| `create_or_update_file` | Write | Medium | https://policylayer.com/tools/github/create-or-update-file.md |
| `create_pull_request` | Write | Medium | https://policylayer.com/tools/github/create-pull-request.md |
| `create_pull_request_with_copilot` | Write | Medium | https://policylayer.com/tools/github/create-pull-request-with-copilot.md |
| `create_repository` | Write | Medium | https://policylayer.com/tools/github/create-repository.md |
| `dismiss_notification` | Write | Medium | https://policylayer.com/tools/github/dismiss-notification.md |
| `fork_repository` | Write | Medium | https://policylayer.com/tools/github/fork-repository.md |
| `issue_write` | Write | Medium | https://policylayer.com/tools/github/issue-write.md |
| `label_write` | Write | Medium | https://policylayer.com/tools/github/label-write.md |
| `manage_notification_subscription` | Write | Medium | https://policylayer.com/tools/github/manage-notification-subscription.md |
| `manage_repository_notification_subscription` | Write | Medium | https://policylayer.com/tools/github/manage-repository-notification-subscription.md |
| `mark_all_notifications_read` | Write | Medium | https://policylayer.com/tools/github/mark-all-notifications-read.md |
| `merge_pull_request` | Write | Medium | https://policylayer.com/tools/github/merge-pull-request.md |
| `pull_request_review_write` | Write | Medium | https://policylayer.com/tools/github/pull-request-review-write.md |
| `push_files` | Write | Medium | https://policylayer.com/tools/github/push-files.md |
| `request_copilot_review` | Write | Medium | https://policylayer.com/tools/github/request-copilot-review.md |
| `star_repository` | Write | Medium | https://policylayer.com/tools/github/star-repository.md |
| `sub_issue_write` | Write | Medium | https://policylayer.com/tools/github/sub-issue-write.md |
| `triage_issue` | Write | Medium | https://policylayer.com/tools/github/triage-issue.md |
| `unstar_repository` | Write | Medium | https://policylayer.com/tools/github/unstar-repository.md |
| `update_gist` | Write | Medium | https://policylayer.com/tools/github/update-gist.md |
| `update_pull_request` | Write | Medium | https://policylayer.com/tools/github/update-pull-request.md |
| `update_pull_request_branch` | Write | Medium | https://policylayer.com/tools/github/update-pull-request-branch.md |

## Tool descriptions

- `delete_file` — Delete a file from a GitHub repository
- `projects_write` — Add, update, or delete project items, or create status updates in a GitHub Project.
- `actions_run_trigger` — Trigger GitHub Actions workflow operations, including running, re-running, cancelling workflow runs, and deleting workflow run logs.
- `assign_copilot_to_issue` — Assign Copilot to a specific issue in a GitHub repository. This tool can help with the following outcomes: - a Pull Request created with source code changes to resolve the issue More information can be found at: - https://docs.github.com…
- `actions_get` — Get details about specific GitHub Actions resources. Use this tool to get details about individual workflows, workflow runs, jobs, and artifacts by their unique IDs.
- `actions_list` — Tools for listing GitHub Actions resources. Use this tool to list workflows in a repository, or list workflow runs, jobs, and artifacts for a specific workflow or workflow run.
- `get_code_scanning_alert` — Get details of a specific code scanning alert in a GitHub repository.
- `get_commit` — Get details for a commit from a GitHub repository
- `get_copilot_job_status` — Get the status of a GitHub Copilot coding agent job. Use this to check if a previously submitted task has completed and to get the pull request URL once it's created. Provide the job ID (from create_pull_request_with_copilot) or pull req…
- `get_copilot_space` — This tool can be used to provide additional context to the chat from a specific Copilot space. If the user mentions the keyword 'Copilot space' with the name and owner of the space, execute this tool. The response includes a table of con…
- `get_dependabot_alert` — Get details of a specific dependabot alert in a GitHub repository.
- `get_discussion` — Get a specific discussion by ID
- `get_discussion_comments` — Get comments from a discussion
- `get_file_contents` — Get the contents of a file or directory from a GitHub repository
- `get_gist` — Get gist content of a particular gist, by gist ID
- `get_global_security_advisory` — Get a global security advisory
- `get_job_logs` — Get logs for GitHub Actions workflow jobs. Use this tool to retrieve logs for a specific job or all failed jobs in a workflow run. For single job logs, provide job_id. For all failed jobs in a run, provide run_id with failed_only=true.
- `get_label` — Get a specific label from a repository.
- `get_latest_release` — Get the latest release in a GitHub repository
- `get_me` — Get details of the authenticated GitHub user. Use this when a request is about the user's own profile for GitHub. Or when information is missing to build other tool calls.
- `get_notification_details` — Get detailed information for a specific GitHub notification, always call this tool when the user asks for details about a specific notification, if you don't know the ID list notifications first.
- `get_release_by_tag` — Get a specific release by its tag name in a GitHub repository
- `get_repository_tree` — Get the tree structure (files and directories) of a GitHub repository at a specific ref or SHA
- `get_secret_scanning_alert` — Get details of a specific secret scanning alert in a GitHub repository.
- `get_tag` — Get details about a specific git tag in a GitHub repository
- `get_team_members` — Get member usernames of a specific team in an organization. Limited to organizations accessible with current credentials
- `get_teams` — Get details of the teams the user is a member of. Limited to organizations accessible with current credentials
- `github_support_docs_search` — Retrieve documentation relevant to answer GitHub product and support questions. Support topics include: GitHub Actions Workflows, Authentication, GitHub Support Inquiries, Pull Request Practices, Repository Maintenance, GitHub Pages, Git…
- `issue_read` — Get information about a specific issue in a GitHub repository.
- `list_branches` — List branches in a GitHub repository
- `list_code_scanning_alerts` — List code scanning alerts in a GitHub repository.
- `list_commits` — Get list of commits of a branch in a GitHub repository. Returns at least 30 results per page by default, but can return more if specified using the perPage parameter (up to 100).
- `list_copilot_spaces` — Retrieves the list of Copilot Spaces accessible to the user, including their names and owners.
- `list_dependabot_alerts` — List dependabot alerts in a GitHub repository.
- `list_discussion_categories` — List discussion categories with their id and name, for a repository or organisation.
- `list_discussions` — List discussions for a repository or organisation.
- `list_gists` — List gists for a user
- `list_global_security_advisories` — List global security advisories from GitHub.
- `list_issue_types` — List supported issue types for repository owner (organization).
- `list_issues` — List issues in a GitHub repository. For pagination, use the 'endCursor' from the previous response's 'pageInfo' in the 'after' parameter.
- `list_label` — List labels from a repository
- `list_notifications` — Lists all GitHub notifications for the authenticated user, including unread notifications, mentions, review requests, assignments, and updates on issues or pull requests. Use this tool whenever the user asks what to work on next, request…
- `list_org_repository_security_advisories` — List repository security advisories for a GitHub organization.
- `list_pull_requests` — List pull requests in a GitHub repository. If the user specifies an author, then DO NOT use this tool and use the search_pull_requests tool instead.
- `list_releases` — List releases in a GitHub repository
- `list_repository_security_advisories` — List repository security advisories for a GitHub repository.
- `list_secret_scanning_alerts` — List secret scanning alerts in a GitHub repository.
- `list_tags` — List git tags in a GitHub repository
- `projects_get` — Get details about specific GitHub Projects resources. Use this tool to get details about individual projects, project fields, and project items by their unique IDs.
- `projects_list` — Tools for listing GitHub Projects resources. Use this tool to list projects for a user or organization, or list project fields and items for a specific project.
- `pull_request_read` — Get information on a specific pull request in GitHub repository.
- `run_secret_scanning` — Scan files, content, or recent changes for secrets such as API keys, passwords, tokens, and credentials. This tool is intended for targeted scans of specific files, snippets, or diffs provided directly as content. It accepts file content…
- `search_code` — Fast and precise code search across ALL GitHub repositories using GitHub's native search engine. Best for finding exact symbols, functions, classes, or specific code patterns.
- `search_issues` — Search for issues in GitHub repositories using issues search syntax already scoped to is:issue
- `search_orgs` — Find GitHub organizations by name, location, or other organization metadata. Ideal for discovering companies, open source foundations, or teams.
- `search_pull_requests` — Search for pull requests in GitHub repositories using issues search syntax already scoped to is:pr
- `search_repositories` — Find GitHub repositories by name, description, readme, topics, or other metadata. Perfect for discovering projects, finding examples, or locating specific repositories across GitHub.
- `search_users` — Find GitHub users by username, real name, or other profile information. Useful for locating developers, contributors, or team members.
- `add_comment_to_pending_review` — Add review comment to the requester's latest pending pull request review. A pending review needs to already exist to call this (check with the user if not sure).
- `add_issue_comment` — Add a comment to a specific issue in a GitHub repository. Use this tool to add comments to pull requests as well (in this case pass pull request number as issue_number), but only if user is not asking specifically to add review comments.
- `add_reply_to_pull_request_comment` — Add a reply to an existing pull request comment. This creates a new comment that is linked as a reply to the specified comment.
- `create_branch` — Create a new branch in a GitHub repository
- `create_gist` — Create a new gist
- `create_or_update_file` — Create or update a single file in a GitHub repository. If updating, you should provide the SHA of the file you want to update. Use this tool to create or update a file in a GitHub repository remotely; do not use it for local file operati…
- `create_pull_request` — Create a new pull request in a GitHub repository.
- `create_pull_request_with_copilot` — Delegate a task to GitHub Copilot coding agent to perform in the background. The agent will create a pull request with the implementation. You should use this tool if the user asks to create a pull request to perform a specific task, or …
- `create_repository` — Create a new GitHub repository in your account or specified organization
- `dismiss_notification` — Dismiss a notification by marking it as read or done
- `fork_repository` — Fork a GitHub repository to your account or specified organization
- `issue_write` — Create a new or update an existing issue in a GitHub repository.
- `label_write` — Perform write operations on repository labels. To set labels on issues, use the 'update_issue' tool.
- `manage_notification_subscription` — Manage a notification subscription: ignore, watch, or delete a notification thread subscription.
- `manage_repository_notification_subscription` — Manage a repository notification subscription: ignore, watch, or delete repository notifications subscription for the provided repository.
- `mark_all_notifications_read` — Mark all notifications as read
- `merge_pull_request` — Merge a pull request in a GitHub repository.
- `pull_request_review_write` — Create and/or submit, delete review of a pull request. Available methods: - create: Create a new review of a pull request. If "event" parameter is provided, the review is submitted. If "event" is omitted, a pending review is created. - s…
- `push_files` — Push multiple files to a GitHub repository in a single commit
- `request_copilot_review` — Request a GitHub Copilot code review for a pull request. Use this for automated feedback on pull requests, usually before requesting a human reviewer.
- `star_repository` — Star a GitHub repository
- `sub_issue_write` — Add a sub-issue to a parent issue in a GitHub repository.
- `triage_issue` — Triage an issue by capturing a focused triage rationale and optionally applying metadata (labels, issue type, and issue fields) in a single operation. Use this tool when: - You are triaging a newly opened or untriaged issue for maintaine…
- `unstar_repository` — Unstar a GitHub repository
- `update_gist` — Update an existing gist
- `update_pull_request` — Update an existing pull request in a GitHub repository.
- `update_pull_request_branch` — Update the branch of a pull request with the latest changes from the base branch.

## Related servers

- UnClick (1658 tools) — https://policylayer.com/tools/io-github-malamutemayhem-unclick-mcp-server.md
- Nodebench (824 tools) — https://policylayer.com/tools/io-github-homenshum-nodebench.md
- Binance MCP Server (734 tools) — https://policylayer.com/tools/nirholas-binance-mcp.md
- Yaver (646 tools) — https://policylayer.com/tools/io-github-kivanccakmak-yaver.md
- MCP Framework Personal (643 tools) — https://policylayer.com/tools/inggerman-mcps.md
- Crow (587 tools) — https://policylayer.com/tools/kh0pper-crow.md
- Fortimanager (584 tools) — https://policylayer.com/tools/jmpijll-fortimanager-mcp.md
- TinyFn (572 tools) — https://policylayer.com/tools/io-tinyfn-tinyfn.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=github · API: https://policylayer.com/registry/api · Recommended policies for every tool: https://policylayer.com/policies/github
