# request_copilot_review

Request a GitHub Copilot code review for a pull request. Use this for automated feedback on pull requests, usually before requesting a human reviewer.

Agent View of the PolicyLayer registry record for `request_copilot_review`. HTML page: https://policylayer.com/tools/github/request-copilot-review

## Facts

- Tool: `request_copilot_review`
- Server: GitHub (`oci:ghcr.io/github/github-mcp-server:1.3.0`) — https://policylayer.com/tools/github.md
- Homepage: https://github.com/github/github-mcp-server
- Risk category: Write (Medium risk)
- Registry record: grade D, identity verified
- Server auth posture: gated
- Server rate-limited: no
- Parameters: 3
- Recommended policy verdict: Rate-limited

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `repo` | string | no | Repository name |
| `owner` | string | no | Repository owner |
| `pullNumber` | number | no | Pull request number |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "request_copilot_review",
    "arguments": {}
  }
}
```

## Why request_copilot_review is rated Medium

This tool triggers a code review request on a pull request, which is a write/modification action on the PR's state. It adds a review request (Copilot as a reviewer) to the pull request. This is reversible (review requests can be removed) and does not delete data, execute arbitrary code, or involve financial transactions. Severity is medium as it modifies PR state and could spam or alter review workflows if misused.

From the tool's own definition: "Request a GitHub Copilot code review for a pull request"

## Use case

AI agents use request_copilot_review to create or update resources in GitHub, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your GitHub environment.

## Recommended policy (PolicyLayer)

Verdict: **Rate-limited**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches GitHub:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "request_copilot_review": {
      "limits": [
        {
          "counter": "request_copilot_review_rate",
          "window": "minute",
          "max": 30,
          "scope": "grant"
        }
      ]
    }
  }
}
```

## Other tools on GitHub (85)

- `delete_file` — Destructive — https://policylayer.com/tools/github/delete-file.md
- `projects_write` — Destructive — https://policylayer.com/tools/github/projects-write.md
- `actions_run_trigger` — Execute — https://policylayer.com/tools/github/actions-run-trigger.md
- `assign_copilot_to_issue` — Execute — https://policylayer.com/tools/github/assign-copilot-to-issue.md
- `actions_get` — Read — https://policylayer.com/tools/github/actions-get.md
- `actions_list` — Read — https://policylayer.com/tools/github/actions-list.md
- `get_code_scanning_alert` — Read — https://policylayer.com/tools/github/get-code-scanning-alert.md
- `get_commit` — Read — https://policylayer.com/tools/github/get-commit.md
- `get_copilot_job_status` — Read — https://policylayer.com/tools/github/get-copilot-job-status.md
- `get_copilot_space` — Read — https://policylayer.com/tools/github/get-copilot-space.md
- `get_dependabot_alert` — Read — https://policylayer.com/tools/github/get-dependabot-alert.md
- `get_discussion` — Read — https://policylayer.com/tools/github/get-discussion.md
- `get_discussion_comments` — Read — https://policylayer.com/tools/github/get-discussion-comments.md
- `get_file_contents` — Read — https://policylayer.com/tools/github/get-file-contents.md
- `get_gist` — Read — https://policylayer.com/tools/github/get-gist.md
- `get_global_security_advisory` — Read — https://policylayer.com/tools/github/get-global-security-advisory.md
- `get_job_logs` — Read — https://policylayer.com/tools/github/get-job-logs.md
- `get_label` — Read — https://policylayer.com/tools/github/get-label.md
- `get_latest_release` — Read — https://policylayer.com/tools/github/get-latest-release.md
- `get_me` — Read — https://policylayer.com/tools/github/get-me.md
- `get_notification_details` — Read — https://policylayer.com/tools/github/get-notification-details.md
- `get_release_by_tag` — Read — https://policylayer.com/tools/github/get-release-by-tag.md
- `get_repository_tree` — Read — https://policylayer.com/tools/github/get-repository-tree.md
- `get_secret_scanning_alert` — Read — https://policylayer.com/tools/github/get-secret-scanning-alert.md
- `get_tag` — Read — https://policylayer.com/tools/github/get-tag.md
- `get_team_members` — Read — https://policylayer.com/tools/github/get-team-members.md
- `get_teams` — Read — https://policylayer.com/tools/github/get-teams.md
- `github_support_docs_search` — Read — https://policylayer.com/tools/github/github-support-docs-search.md
- `issue_read` — Read — https://policylayer.com/tools/github/issue-read.md
- `list_branches` — Read — https://policylayer.com/tools/github/list-branches.md
- …and 55 more: https://policylayer.com/tools/github.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=github · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/github
