Search / io.github.davidweb3-ctrl/github
github
L0 · runs locallyGitHub MCP Server - List PRs, issues, repo info, and search code
v1.0.0 · active · repository · descriptor JSON · versions
Search / io.github.davidweb3-ctrl/github
GitHub MCP Server - List PRs, issues, repo info, and search code
v1.0.0 · active · repository · descriptor JSON · versions
{
"mcpServers": {
"github": {
"command": "npx",
"args": [
"-y",
"@davidweb3-ctrl/[email protected]"
],
"env": {
"GITHUB_TOKEN": "${GITHUB_TOKEN}"
}
}
}
}claude mcp add github -e "GITHUB_TOKEN=${GITHUB_TOKEN}" -- npx -y @davidweb3-ctrl/[email protected][mcp_servers.github]
command = "npx"
args = ["-y", "@davidweb3-ctrl/[email protected]"]
env = { "GITHUB_TOKEN" = "${GITHUB_TOKEN}" }
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"github": {
"type": "local",
"command": [
"npx",
"-y",
"@davidweb3-ctrl/[email protected]"
],
"enabled": true,
"environment": {
"GITHUB_TOKEN": "{env:GITHUB_TOKEN}"
}
}
}
}{
"mcpServers": {
"github": {
"command": "npx",
"args": [
"-y",
"@davidweb3-ctrl/[email protected]"
],
"env": {
"GITHUB_TOKEN": "${GITHUB_TOKEN}"
}
}
},
"deeplink": "cursor://anysphere.cursor-deeplink/mcp/install?name=github&config=eyJjb21tYW5kIjoibnB4IiwiYXJncyI6WyIteSIsIkBkYXZpZHdlYjMtY3RybC9tY3AtZ2l0aHViLXNlcnZlckAxLjAuMCJdLCJlbnYiOnsiR0lUSFVCX1RPS0VOIjoiJHtHSVRIVUJfVE9LRU59In19"
}{
"servers": {
"github": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"@davidweb3-ctrl/[email protected]"
],
"env": {
"GITHUB_TOKEN": "${GITHUB_TOKEN}"
}
}
}
}{
"mcpServers": {
"github": {
"command": "npx",
"args": [
"-y",
"@davidweb3-ctrl/[email protected]"
],
"env": {
"GITHUB_TOKEN": "${GITHUB_TOKEN}"
}
}
}
}extensions:
"github":
enabled: true
name: "github"
type: stdio
cmd: "npx"
args:
- "-y"
- "@davidweb3-ctrl/[email protected]"
envs:
"GITHUB_TOKEN": "${GITHUB_TOKEN}"
timeout: 300
Placeholders to fill from your own secret store: ${GITHUB_TOKEN}. The registry never accepts secret values.
This is a local package: the command runs on your machine.
Not scored: fewer than three checks apply, usually because no remote answered a credential-free probe or the server is a local package.
protocol.modern, protocol.stateless, protocol.transport, protocol.list_ttlno remote answered a protocol handshake (not probed yet, unreachable, or local-only)auth.prm, auth.as_metadata, auth.cimdno remote uses OAuthauth.secret_in_urlno templated URLtools.descriptions, tools.description_length, tools.schemas, tools.annotations, tools.directory_hints, tools.token_cost, tools.api_dumptool list unknown (behind auth, not probed, or empty)stability.changes, stability.rug_pulltool list unknowndeps.known_vulnsno known advisory in 113 resolved packagesdeps.mcp_sdk_version@modelcontextprotocol/sdk 1.30.1 has 1 known advisory (GHSA-6qxp-vccf-f47h); update @modelcontextprotocol/sdk to 1.31.0 or laterdeps.resolvable@davidweb3-ctrl/[email protected] resolved: 113 packagesNo tool definition changes recorded. A server's first observation is its baseline; later probes record what changes.
Checks run on what our credential-free, read-only probes observe; tools are never called and no code audit is performed. How it is computed.
+repository +namespace-matches-repo ~liveness-unmeasured ~updated-172d-ago
Derived from observable signals (official registry feed and our own credential-free probes); no code audit performed. How it is computed.
@davidweb3-ctrl/[email protected] npm112 dependencies, resolved · MCP SDK @modelcontextprotocol/sdk 1.30.1 · advisories checked 2026-10-09
| advisory | severity | package | fixed in |
|---|---|---|---|
| GHSA-6qxp-vccf-f47hMCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server | high | @modelcontextprotocol/[email protected]MCP SDK, direct | fixed in 1.31.0 |
Dependency graphs from deps.dev; advisories from OSV.dev, including the GitHub Advisory Database and the PyPI Advisory Database; all CC BY 4.0. The graph is what a clean install of this version resolves today; nothing was installed or run. How it is checked.
| package | registry | version | runtime | secrets |
|---|---|---|---|---|
@davidweb3-ctrl/mcp-github-server | npm | 1.0.0 | – | GITHUB_TOKEN |
No tools observed. Local packages are never executed by the registry.
Schemas: list_tools.
{
"name": "io.github.davidweb3-ctrl/github",
"$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
"version": "1.0.0",
"packages": [
{
"version": "1.0.0",
"transport": {
"type": "stdio"
},
"identifier": "@davidweb3-ctrl/mcp-github-server",
"registryType": "npm",
"environmentVariables": [
{
"name": "GITHUB_TOKEN",
"format": "string",
"isSecret": true,
"isRequired": true,
"description": "GitHub Personal Access Token"
}
]
}
],
"repository": {
"url": "https://github.com/davidweb3-ctrl/mcp-github-server",
"source": "github"
},
"description": "GitHub MCP Server - List PRs, issues, repo info, and search code"
}