projects_list
Tools for listing GitHub Projects resources. Use this tool to list projects for a user or organization, or list project fields and items for a specific project.
This record as markdown: /tools/github/projects-list.md
What projects_list does on GitHub
AI agents call projects_list to retrieve information from GitHub without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.
| Parameter | Type | Required | Description |
|---|---|---|---|
after | string | — | Forward pagination cursor from previous pageInfo.nextCursor. |
owner | string | — | The owner (user or organization login). The name is not case sensitive. |
query | string | — | Filter/query string. For list_projects: filter by title text and state (e.g. "roadmap is:open"). For list_project_items: advanced filtering using GitHub's proje |
before | string | — | Backward pagination cursor from previous pageInfo.prevCursor (rare). |
fields | array | — | Field IDs to include when listing project items (e.g. ["102589", "985201"]). CRITICAL: Always provide to get field values. Without this, only titles returned. O |
method | string | — | The action to perform |
per_page | number | — | Results per page (max 50) |
owner_type | string | — | Owner type (user or org). If not provided, will automatically try both. |
project_number | number | — | The project's number. Required for 'list_project_fields', 'list_project_items', and 'list_project_status_updates' methods. |
Parameters from the server's own tool schema.
Why projects_list is rated Low
This tool retrieves and queries project data without creating, modifying, deleting, or executing any operations. It is a pure read operation that returns information about GitHub Projects, their fields, and items. No reversible or irreversible changes are made.
From the tool's definition Tool name 'projects_list' and description states 'listing GitHub Projects resources' with actions to 'list projects for a user or organization, or list project fields and items for a specific project' - these are query operations with no side effects.
Risk signalsAccepts freeform code/query input (query)
Attacks that exploit this kind of access
The rule that runs projects_list safely
PolicyLayer is an MCP gateway: it sits between your AI agents and GitHub, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For projects_list, this is the rule to start with:
projects_list is read-only, so it stays allowed. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect GitHub, apply this rule, and every projects_list call is checked against it from then on.
Questions about projects_list
Tools for listing GitHub Projects resources. Use this tool to list projects for a user or organization, or list project fields and items for a specific project. It is categorised as a Read tool in the GitHub MCP Server, which means it retrieves data without modifying state.
projects_list accepts 9 parameters: after, owner, query, before, fields, method, per_page, owner_type, project_number. The full parameter table on this page comes from the server's own tool schema.
Register the GitHub MCP server in PolicyLayer and add a rule for projects_list: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches GitHub. Nothing to install.
projects_list is a Read tool with low risk. Read-only tools are generally safe to allow by default.
Yes. Add a rate_limit block to the projects_list rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for projects_list. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
projects_list is provided by the GitHub MCP server (oci:ghcr.io/github/github-mcp-server:1.3.0). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on GitHub, and thousands of servers like it.
This server
Across the catalogue