# search_repositories

Find GitHub repositories by name, description, readme, topics, or other metadata. Perfect for discovering projects, finding examples, or locating specific repositories across GitHub.

Agent View of the PolicyLayer registry record for `search_repositories`. HTML page: https://policylayer.com/tools/github/search-repositories

## Facts

- Tool: `search_repositories`
- Server: GitHub (`oci:ghcr.io/github/github-mcp-server:1.3.0`) — https://policylayer.com/tools/github.md
- Homepage: https://github.com/github/github-mcp-server
- Risk category: Read (Low risk)
- Registry record: grade D, identity verified
- Server auth posture: gated
- Server rate-limited: no
- Parameters: 6
- Recommended policy verdict: Allowed

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `page` | number | no | Page number for pagination (min 1) |
| `sort` | string | no | Sort repositories by field, defaults to best match |
| `order` | string | no | Sort order |
| `query` | string | no | Repository search query. Examples: 'machine learning in:name stars:>1000 language:python', 'topic:react', 'user:facebook'. Supports advanced search syntax for p |
| `perPage` | number | no | Results per page for pagination (min 1, max 100) |
| `minimal_output` | boolean | no | Return minimal repository information (default: true). When false, returns full GitHub API repository objects. |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "search_repositories",
    "arguments": {}
  }
}
```

## Why search_repositories is rated Low

This tool performs repository discovery and retrieval operations without side effects. It queries public GitHub metadata (names, descriptions, readmes, topics) but does not create, modify, delete, or execute any code. This is a classic read operation with no blast radius if misused by an AI agent—at worst it returns unintended search results.

From the tool's own definition: "Tool description explicitly states it 'Find[s] GitHub repositories by name, description, readme, topics, or other metadata' with no mention of modification, deletion, or execution capabilities."

Risk signals: Accepts freeform code/query input (query)

## Use case

AI agents call search_repositories to retrieve information from GitHub without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.

## Recommended policy (PolicyLayer)

Verdict: **Allowed**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches GitHub:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "search_repositories": {}
  }
}
```

## Other tools on GitHub (85)

- `delete_file` — Destructive — https://policylayer.com/tools/github/delete-file.md
- `projects_write` — Destructive — https://policylayer.com/tools/github/projects-write.md
- `actions_run_trigger` — Execute — https://policylayer.com/tools/github/actions-run-trigger.md
- `assign_copilot_to_issue` — Execute — https://policylayer.com/tools/github/assign-copilot-to-issue.md
- `actions_get` — Read — https://policylayer.com/tools/github/actions-get.md
- `actions_list` — Read — https://policylayer.com/tools/github/actions-list.md
- `get_code_scanning_alert` — Read — https://policylayer.com/tools/github/get-code-scanning-alert.md
- `get_commit` — Read — https://policylayer.com/tools/github/get-commit.md
- `get_copilot_job_status` — Read — https://policylayer.com/tools/github/get-copilot-job-status.md
- `get_copilot_space` — Read — https://policylayer.com/tools/github/get-copilot-space.md
- `get_dependabot_alert` — Read — https://policylayer.com/tools/github/get-dependabot-alert.md
- `get_discussion` — Read — https://policylayer.com/tools/github/get-discussion.md
- `get_discussion_comments` — Read — https://policylayer.com/tools/github/get-discussion-comments.md
- `get_file_contents` — Read — https://policylayer.com/tools/github/get-file-contents.md
- `get_gist` — Read — https://policylayer.com/tools/github/get-gist.md
- `get_global_security_advisory` — Read — https://policylayer.com/tools/github/get-global-security-advisory.md
- `get_job_logs` — Read — https://policylayer.com/tools/github/get-job-logs.md
- `get_label` — Read — https://policylayer.com/tools/github/get-label.md
- `get_latest_release` — Read — https://policylayer.com/tools/github/get-latest-release.md
- `get_me` — Read — https://policylayer.com/tools/github/get-me.md
- `get_notification_details` — Read — https://policylayer.com/tools/github/get-notification-details.md
- `get_release_by_tag` — Read — https://policylayer.com/tools/github/get-release-by-tag.md
- `get_repository_tree` — Read — https://policylayer.com/tools/github/get-repository-tree.md
- `get_secret_scanning_alert` — Read — https://policylayer.com/tools/github/get-secret-scanning-alert.md
- `get_tag` — Read — https://policylayer.com/tools/github/get-tag.md
- `get_team_members` — Read — https://policylayer.com/tools/github/get-team-members.md
- `get_teams` — Read — https://policylayer.com/tools/github/get-teams.md
- `github_support_docs_search` — Read — https://policylayer.com/tools/github/github-support-docs-search.md
- `issue_read` — Read — https://policylayer.com/tools/github/issue-read.md
- `list_branches` — Read — https://policylayer.com/tools/github/list-branches.md
- …and 55 more: https://policylayer.com/tools/github.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=github · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/github
