Skip to main content
Glama

20 Best GitHub MCP Servers, Compared (October 2026)

Updated 20 of 1,731 GitHub servers in the Glama registryRebuilt weekly

The short answer

For most readers, the server to reach for is GitHub MCP Server (github/github-mcp-server). It is GitHub's official MCP Server, has 33,210 GitHub stars and 696 stars gained per 30 days, and its default branch had a commit 11 days ago with 184 commits in the last 12 weeks. It is designed to connect an AI assistant to GitHub in VS Code as a remote HTTP MCP server at api.githubcopilot.com/mcp/ using OAuth or a PAT. If your task is retrieving specific code symbols from an indexed repository instead of general GitHub access, github-codemunch-mcp (jgravelle/jcodemunch-mcp) is the better answer: it exposes 7 tools, its tool descriptions are graded A, and its default branch had a commit 0 days ago.

Whichever you choose, give it the narrowest access that still works (a read-only credential, a replica, a scratch account), and widen it only once you have watched what your agent actually asks for.

Glama operates the MCP registry these numbers are measured from, and sells MCP hosting and a gateway. No position on this page is paid for. How the registry is built.

Quick picks

  • 1GitHub MCP Server : Connecting an AI assistant to GitHub in VS Code: it installs as a remote HTTP MCP server at api.githubcopilot.com/mcp/ using OAuth or a PAT.
  • 2github-codemunch-mcp : Retrieving specific code symbols from an indexed repository: it exposes seven tools for tree-sitter indexing, file outlines, symbol search, and exact source retrieval.
  • 3Octocode MCP : Researching code across GitHub repositories and local checkouts in one session: it pairs GitHub search, file, and pull request tools with local ripgrep, filesystem, and LSP tools.
  • 4mcp-github-project-manager : Sprint and milestone tracking on GitHub Projects V2: it exposes 84 tools covering roadmaps, milestones, sprint metrics, draft issues, and pull request reviews.
  • 5idea-reality-mcp : Before building a product idea: it exposes idea_check to check whether that idea already exists.

Which one, for your situation

Your situationWhat to use
Connecting an AI assistant to GitHub in VS CodeUse GitHub MCP Server (github/github-mcp-server), which installs as a remote HTTP MCP server at api.githubcopilot.com/mcp/ using OAuth or a PAT.
Fetching exact code symbols from an indexed repositoryUse github-codemunch-mcp (jgravelle/jcodemunch-mcp), which exposes 7 tools for tree-sitter indexing, file outlines, symbol search, and exact source retrieval and had a commit 0 days ago.
Tracking sprints and milestones on GitHub Projects V2Use mcp-github-project-manager (kunwarVivek/mcp-github-project-manager), which exposes 84 tools for roadmaps, milestones, sprint metrics, draft issues, and pull request reviews.
Checking whether a product idea already existsUse idea-reality-mcp (mnemox-ai/idea-reality-mcp), which exposes idea_check to check whether that idea already exists and had a commit 9 days ago.
Auditing a GitHub org's security postureUse github-security-mcp (badchars/github-security-mcp), which exposes 39 tools across org settings, repository config, workflows, secrets, supply chain, and access control, but note its default branch had a commit 197 days ago.
Securing an agent that calls MCP servers with secretsUse pipelock (luckyPipewrench/pipelock), which proxies MCP traffic and scans bidirectionally for credential leaks, prompt injection, and tool description poisoning.

Top MCP servers for GitHub

Best forProfile
1Connecting an AI assistant to GitHub in VS Code: it installs as a remote HTTP MCP server at api.githubcopilot.com/mcp/ using OAuth or a PAT.Community favourite33,210+69611 days ago92.4
2Retrieving specific code symbols from an indexed repository: it exposes seven tools for tree-sitter indexing, file outlines, symbol search, and exact source retrieval.Community favourite2,715+87today78.7
3Researching code across GitHub repositories and local checkouts in one session: it pairs GitHub search, file, and pull request tools with local ripgrep, filesystem, and LSP tools.Community favourite944+2833 days ago67.9
4Sprint and milestone tracking on GitHub Projects V2: it exposes 84 tools covering roadmaps, milestones, sprint metrics, draft issues, and pull request reviews.Steady101+95 days ago67.5
5Before building a product idea: it exposes idea_check to check whether that idea already exists.Community favourite821+199 days ago61.9
6Debugging a library or cloud error and needing StackOverflow or GitHub Issue answers, not snippets: it returns full conversations and structured content in one call.Community favourite395+18today60.0
7Preventing duplicate code before committing: it exposes check_duplication, get_file_clones, get_statistics, and check_current_directory against the scanned project.Community favourite6,273+181today56.9
8Finding a previously starred repository by description rather than keyword: it exposes a natural language search tool backed by Cloudflare AutoRAG over repository READMEs.Steady116+4yesterday56.6
9AI assistants needing current documentation and code for a specific GitHub repository: it exposes remote MCP endpoints such as gitmcp.io/{owner}/{repo} and gitmcp.io/docs.Abandoned but popular8,417+76142 days ago56.3
10Incident response and dependency triage on a known CVE list: 41 tools pull NVD, EPSS, KEV and OSV data and rank vulnerabilities by exploitation risk.Community favourite28+1183 days ago54.4
11Preparing AI skills or RAG knowledge from mixed sources: it scrapes GitHub repos, docs sites, PDFs, and videos and exports to vector databases.Community favourite15,020+2137 days ago52.9
12Static analysis before merge in an MCP-compatible coding agent: it exposes twelve tools for dead code, security, secrets, quality, and diff validation.Community favourite836+381today52.8
13Securing an agent that calls MCP servers with secrets: it proxies MCP traffic and scans bidirectionally for credential leaks, prompt injection, and tool description poisoning.Community favourite905+101today50.6
14Autonomous spec-driven builds inside a repository, where the MCP client needs project state, task-queue, memory, code-search, and verification tools over stdio.Community favourite1,072+22today49.2
15Teams automating GitHub Actions, pull requests, code search, and repository management from an MCP client: it documents compact, JSON, and Markdown response formats.Steady5+161 days ago49.2
16Running authorized coding, bug-fixing, tests or refactors in Claude Code or Cursor while capping session spend: it enforces budgets, preflight validation and verifier safety gates.Community favourite192+181today47.8
17Auditing a GitHub org's security posture from an AI agent: 39 tools across org settings, repository config, workflows, secrets, supply chain and access control.Dormant13+1197 days ago46.2
18Securing GitHub-connected agents that run with permissions skipped: it hooks every tool call, blocking credential-file reads and holding destructive git or shell actions for review.Community favourite216+8today45.7
19Managing AI personas and other reusable elements in a local portfolio: it exposes five tools spanning create, read, update, delete and execute.Steady44+46 days ago44.5
20Summarizing a GitHub organization's issues, discussions, and pull requests beyond the standard API item limit: it stores data locally and returns token-efficient Markdown.Dormant780235 days ago43.8

The ranking, with the evidence

Each position is a weighted mean of adoption (40%), maintenance (24%), momentum (14%), tool description quality (13%) and trust (9%), multiplied by three attenuators: how directly the server is about GitHub (named for it, declaring it, tagged with it, or merely mentioning it), whether its repository is still moving, and how much independent evidence of adoption it has. Open the score on any entry to see every number, including the ones marked ≈, which were imputed from the median of the other candidates rather than measured. The maintenance grade on each entry is mostly issue responsiveness, release recency and open security alerts rather than commits, so a recent commit beside a low grade is two different measurements rather than a contradiction.

  • Abandoned but popular: People use it, but its default branch has stopped moving. Fine to keep running, risky to adopt.
  • Community favourite: Widely adopted and still actively maintained.
  • Dormant: Neither changing nor widely adopted. Here because it still matches the search.
  • Emerging: Small audience, growing quickly, maintained. The bet with the most upside.
  • Steady: Maintained, modest audience, no surprises in either direction.
  • Best for: Connecting an AI assistant to GitHub in VS Code: it installs as a remote HTTP MCP server at api.githubcopilot.com/mcp/ using OAuth or a PAT.

    The GitHub MCP Server provides GitHub access through a remote HTTP MCP endpoint at api.githubcopilot.com/mcp/ with OAuth or PAT authentication, plus a local version for hosts without remote support. Before choosing it, note that the remote server requires a compatible MCP host with remote server support and any applicable policies enabled.

    GitHub stars
    33,210
    Stars over the last 90 days: 31,156 at the earliest of 40 readings and 33,210 at the latest, up 2,054.
    Stars / 30 days
    +696
    npm / typical week
    Ships no npm package
    PyPI / typical week
    no attributed package
    Tools exposed
    never inspected
    Last commit
    11 days ago
    Commits / 12 weeks
    184
    Weekly commits over the last 12 weeks, oldest first: 18, 18, 15, 7, 12, 12, 61, 15, 21, 3, 2, 0. 184 in total, and the last figure is the current week so far.
    Maintenance grade
    A
    Tool descriptions
    Not graded
    Score 92.4: show every number behind it
    • Adoption100 / 100 · weight 40%
      • GitHub stars100
      • npm downloadsnot measured
        no npm package
      • Used through Glamanot measured
        not used through Glama in the last 30 days
    • Maintenance100 / 100 · weight 24%
      • Last commit touching this server100
      • Repository maintenance grade100
      • Commit cadence100
    • Momentum76 / 100 · weight 14%
      • Stars gained, relative to size59
      • Stars gained, absolute100
      • npm download trendnot measured
        no download history for the selected registry
    • Tool quality≈68 / 100 · weight 13%
      • Tool description quality≈68
        tool descriptions not yet scored
      • Built and inspected by Glamanot measured
        never built and inspected by Glama
    • Trust100 / 100 · weight 9%
      • License100
      • Published by the vendor it integrates100
    Weighted mean of the five
    92.4
    × relevance: the keyword is dedicated here
    1.00
    × continuity: actively changing
    1.00
    × evidence: widely adopted
    1.00
    Composite score
    92.4
  • Best for: Retrieving specific code symbols from an indexed repository: it exposes seven tools for tree-sitter indexing, file outlines, symbol search, and exact source retrieval.

    github-codemunch-mcp indexes a GitHub repository's source code locally, parsing it with tree-sitter to store symbol signatures and summaries, and it exposes seven tools for listing indexed repos, viewing file trees and outlines, searching symbols, and fetching one or more symbol sources. Before choosing it, note that it requires an indexing step per repository (index_repo) and keeps that index in local storage, so it covers exploration and retrieval of already indexed code rather than editing repositories or querying them without an index.

    GitHub stars
    2,715
    Stars over the last 90 days: 1,969 at the earliest of 53 readings and 2,715 at the latest, up 746.
    Stars / 30 days
    +87
    npm / typical week
    Ships no npm package
    PyPI / typical week
    17.8K
    jcodemunch-mcp
    Tools exposed
    7
    Last commit
    today
    Commits / 12 weeks
    1,049
    Weekly commits over the last 12 weeks, oldest first: 35, 22, 57, 90, 90, 81, 120, 115, 168, 176, 43, 52. 1,049 in total, and the last figure is the current week so far.
    Maintenance grade
    A
    Tool descriptions
    A
    Score 78.7: show every number behind it
    • Adoption93 / 100 · weight 40%
      • GitHub stars86
      • PyPI downloads45
        PyPI downloads show no weekday rhythm; halved
      • Used through Glamanot measured
        not used through Glama in the last 30 days
    • Maintenance100 / 100 · weight 24%
      • Last commit touching this server100
      • Repository maintenance grade100
      • Commit cadence100
    • Momentum56 / 100 · weight 14%
      • Stars gained, relative to size72
      • Stars gained, absolute78
      • PyPI download trend0
    • Tool quality76 / 100 · weight 13%
      • Tool description quality68
      • Built and inspected by Glama100
    • Trust0 / 100 · weight 9%
      • License0
      • Published by the vendor it integratesnot measured
        not published by the vendor it integrates
    Weighted mean of the five
    78.7
    × relevance: the keyword is dedicated here
    1.00
    × continuity: actively changing
    1.00
    × evidence: widely adopted
    1.00
    Composite score
    78.7
  • 3

    Octocode MCP

    Community favouriteNo change
    bgauryy/octocode ↗

    Best for: Researching code across GitHub repositories and local checkouts in one session: it pairs GitHub search, file, and pull request tools with local ripgrep, filesystem, and LSP tools.

    Octocode MCP exposes 13 tools split between GitHub API operations (code, repository, and pull request search, file reads, repo structure), local work over ripgrep, filesystem, and LSP, and npm/PyPI package lookup, and the README documents the same set running either as an MCP server or as a CLI. The LSP tools require a lineHint obtained from localSearchCode first, Node.js 20.12+ is a prerequisite, and GitHub authentication is optional but needed for private repositories and higher API rate limits.

    GitHub stars
    944
    Stars over the last 90 days: 879 at the earliest of 26 readings and 944 at the latest, up 65.
    Stars / 30 days
    +28
    npm / typical week
    2.3K
    PyPI / typical week
    no attributed package
    Tools exposed
    13
    Last commit
    33 days ago
    Commits / 12 weeks
    24
    Weekly commits over the last 12 weeks, oldest first: 0, 4, 4, 0, 6, 7, 2, 1, 0, 0, 0, 0. 24 in total, and the last figure is the current week so far.
    Maintenance grade
    A
    Tool descriptions
    A
    Score 67.9: show every number behind it
    • Adoption85 / 100 · weight 40%
      • GitHub stars74
      • npm downloads72
      • Used through Glamanot measured
        not used through Glama in the last 30 days
    • Maintenance97 / 100 · weight 24%
      • Last commit touching this server100
      • Repository maintenance grade100
      • Commit cadence85
    • Momentum55 / 100 · weight 14%
      • Stars gained, relative to size66
      • Stars gained, absolute59
      • npm download trend33
    • Tool quality100 / 100 · weight 13%
      • Tool description quality93
      • Built and inspected by Glama100
    • Trust100 / 100 · weight 9%
      • License100
      • Published by the vendor it integratesnot measured
        not published by the vendor it integrates
    Weighted mean of the five
    87.1
    × relevance: the keyword is declared here
    0.78
    × continuity: actively changing
    1.00
    × evidence: widely adopted
    1.00
    Composite score
    67.9
  • Best for: Sprint and milestone tracking on GitHub Projects V2: it exposes 84 tools covering roadmaps, milestones, sprint metrics, draft issues, and pull request reviews.

    The server implements the Model Context Protocol over GitHub Projects V2, exposing 84 tools that create and update projects, roadmaps, milestones, sprints, issues, draft issues, and pull requests, plus progress metrics for milestones and sprints. Choosing it does assume a GitHub Projects V2 board to run against, since its README states that all state lives in GitHub issues, project fields, and comments, with no external database or other infrastructure required.

    GitHub stars
    101
    Stars over the last 90 days: 91 at the earliest of 81 readings and 101 at the latest, up 10.
    Stars / 30 days
    +9
    npm / typical week
    56
    PyPI / typical week
    no attributed package
    Tools exposed
    84
    Last commit
    5 days ago
    Commits / 12 weeks
    81
    Weekly commits over the last 12 weeks, oldest first: 0, 25, 0, 0, 38, 0, 0, 0, 1, 4, 0, 13. 81 in total, and the last figure is the current week so far.
    Maintenance grade
    C
    Tool descriptions
    C
    Score 67.5: show every number behind it
    • Adoption56 / 100 · weight 40%
      • GitHub stars50
      • npm downloads37
      • Used through Glamanot measured
        not used through Glama in the last 30 days
    • Maintenance89 / 100 · weight 24%
      • Last commit touching this server100
      • Repository maintenance grade55
      • Commit cadence100
    • Momentum59 / 100 · weight 14%
      • Stars gained, relative to size76
      • Stars gained, absolute40
      • npm download trend52
    • Tool quality51 / 100 · weight 13%
      • Tool description quality43
      • Built and inspected by Glama100
    • Trust100 / 100 · weight 9%
      • License100
      • Published by the vendor it integratesnot measured
        not published by the vendor it integrates
    Weighted mean of the five
    67.5
    × relevance: the keyword is dedicated here
    1.00
    × continuity: actively changing
    1.00
    × evidence: widely adopted
    1.00
    Composite score
    67.5
  • Best for: Before building a product idea: it exposes idea_check to check whether that idea already exists.

    idea-reality-mcp exposes one MCP tool, idea_check, which checks a plain-English product idea against external sources and returns a reality signal with competitor evidence, trend direction, and pivot suggestions. It is scoped to that pre-build check, so it does not cover general GitHub repository, issue, or pull request operations.

    GitHub stars
    821
    Stars over the last 90 days: 754 at the earliest of 13 readings and 822 at the latest, up 68.
    Stars / 30 days
    +19
    npm / typical week
    Ships no npm package
    PyPI / typical week
    70
    idea-reality-mcp
    Tools exposed
    1
    Last commit
    9 days ago
    Commits / 12 weeks
    37
    Weekly commits over the last 12 weeks, oldest first: 27, 1, 0, 2, 0, 2, 0, 0, 0, 0, 1, 0. 33 in total, and the last figure is the current week so far.
    Maintenance grade
    C
    Tool descriptions
    A
    Score 61.9: show every number behind it
    • Adoption76 / 100 · weight 40%
      • GitHub stars73
      • PyPI downloads20
        PyPI downloads show no weekday rhythm; halved
      • Used through Glamanot measured
        not used through Glama in the last 30 days
    • Maintenance89 / 100 · weight 24%
      • Last commit touching this server100
      • Repository maintenance grade55
      • Commit cadence100
    • Momentum47 / 100 · weight 14%
      • Stars gained, relative to size57
      • Stars gained, absolute52
      • PyPI download trend24
    • Tool quality93 / 100 · weight 13%
      • Tool description quality85
      • Built and inspected by Glama100
    • Trust100 / 100 · weight 9%
      • License100
      • Published by the vendor it integratesnot measured
        not published by the vendor it integrates
    Weighted mean of the five
    79.4
    × relevance: the keyword is declared here
    0.78
    × continuity: actively changing
    1.00
    × evidence: widely adopted
    1.00
    Composite score
    61.9
  • Best for: Debugging a library or cloud error and needing StackOverflow or GitHub Issue answers, not snippets: it returns full conversations and structured content in one call.

    Its README documents a web_search interface returning titles, links, snippets, and best-effort Markdown page content, and a get_content interface for retrieving Markdown from a URL, with structured content from StackOverflow, GitHub Issues, arXiv, and Wikipedia. No npm package is published and no PyPI package is attributed to it.

    GitHub stars
    395
    Stars over the last 90 days: 353 at the earliest of 18 readings and 395 at the latest, up 42.
    Stars / 30 days
    +18
    npm / typical week
    Ships no npm package
    PyPI / typical week
    no attributed package
    Tools exposed
    never inspected
    Last commit
    today
    Commits / 12 weeks
    304
    Weekly commits over the last 12 weeks, oldest first: 0, 4, 0, 16, 0, 0, 4, 0, 158, 96, 26, 0. 304 in total, and the last figure is the current week so far.
    Maintenance grade
    A
    Tool descriptions
    Not graded
    Score 60.0: show every number behind it
    • Adoption65 / 100 · weight 40%
      • GitHub stars65
      • npm downloadsnot measured
        no npm package
      • Used through Glamanot measured
        not used through Glama in the last 30 days
    • Maintenance100 / 100 · weight 24%
      • Last commit touching this server100
      • Repository maintenance grade100
      • Commit cadence100
    • Momentum65 / 100 · weight 14%
      • Stars gained, relative to size75
      • Stars gained, absolute51
      • npm download trendnot measured
        no download history for the selected registry
    • Tool quality≈68 / 100 · weight 13%
      • Tool description quality≈68
        tool descriptions not yet scored
      • Built and inspected by Glamanot measured
        never built and inspected by Glama
    • Trust100 / 100 · weight 9%
      • License100
      • Published by the vendor it integratesnot measured
        not published by the vendor it integrates
    Weighted mean of the five
    76.9
    × relevance: the keyword is declared here
    0.78
    × continuity: actively changing
    1.00
    × evidence: widely adopted
    1.00
    Composite score
    60.0
  • 7

    jscpd

    Community favouriteNo change
    kucherenko/jscpd ↗

    Best for: Preventing duplicate code before committing: it exposes check_duplication, get_file_clones, get_statistics, and check_current_directory against the scanned project.

    jscpd's built-in MCP server runs over stdio and exposes four tools: check_duplication for snippets, get_file_clones and get_statistics for the last scan, and check_current_directory to re-scan the paths it was started with. The scope is the scanned project: results come from the last scan or the paths the server was started with, so changing those paths requires starting jscpd --mcp with the new project.

    GitHub stars
    6,273
    Stars over the last 90 days: 6,067 at the earliest of 18 readings and 6,273 at the latest, up 206.
    Stars / 30 days
    +181
    npm / typical week
    Ships no npm package
    PyPI / typical week
    no attributed package
    Tools exposed
    4
    Last commit
    today
    Commits / 12 weeks
    449
    Weekly commits over the last 12 weeks, oldest first: 28, 4, 10, 11, 11, 74, 49, 16, 53, 65, 80, 48. 449 in total, and the last figure is the current week so far.
    Maintenance grade
    A
    Tool descriptions
    A
    Score 56.9: show every number behind it
    • Adoption95 / 100 · weight 40%
      • GitHub stars95
      • npm downloadsnot measured
        no npm package
      • Used through Glamanot measured
        not used through Glama in the last 30 days
    • Maintenance100 / 100 · weight 24%
      • Last commit touching this server100
      • Repository maintenance grade100
      • Commit cadence100
    • Momentum78 / 100 · weight 14%
      • Stars gained, relative to size69
      • Stars gained, absolute91
      • npm download trendnot measured
        no download history for the selected registry
    • Tool quality100 / 100 · weight 13%
      • Tool description quality93
      • Built and inspected by Glama100
    • Trust100 / 100 · weight 9%
      • License100
      • Published by the vendor it integrates100
    Weighted mean of the five
    94.8
    × relevance: the keyword is tagged here
    0.60
    × continuity: actively changing
    1.00
    × evidence: widely adopted
    1.00
    Composite score
    56.9
  • Best for: Finding a previously starred repository by description rather than keyword: it exposes a natural language search tool backed by Cloudflare AutoRAG over repository READMEs.

    GitHub Stars MCP Server fetches a GitHub account's starred repositories and their README files into Cloudflare R2, builds an AutoRAG index over that content, and serves it through a streamable HTTP endpoint with a search_github_stars tool that accepts a natural language query. Before choosing it, note that it is self-hosted rather than a hosted service: it requires a Cloudflare account with an R2 bucket and AutoRAG instance configured, a GitHub personal access token with repo scope, and an MCP_API_KEY, since requests are authenticated with a bearer token.

    GitHub stars
    116
    Stars over the last 90 days: 111 at the earliest of 14 readings and 116 at the latest, up 5.
    Stars / 30 days
    +4
    npm / typical week
    downloads not counted
    PyPI / typical week
    no attributed package
    Tools exposed
    never inspected
    Last commit
    yesterday
    Commits / 12 weeks
    15
    Weekly commits over the last 12 weeks, oldest first: 4, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1. 15 in total, and the last figure is the current week so far.
    Maintenance grade
    B
    Tool descriptions
    Not graded
    Score 56.6: show every number behind it
    • Adoption52 / 100 · weight 40%
      • GitHub stars52
      • npm downloadsnot measured
        npm names no repository for mcp-github-stars, so its downloads cannot be attributed
      • Used through Glamanot measured
        not used through Glama in the last 30 days
    • Maintenance92 / 100 · weight 24%
      • Last commit touching this server100
      • Repository maintenance grade80
      • Commit cadence85
    • Momentum43 / 100 · weight 14%
      • Stars gained, relative to size52
      • Stars gained, absolute29
      • npm download trendnot measured
        no download history for the selected registry
    • Tool quality≈68 / 100 · weight 13%
      • Tool description quality≈68
        tool descriptions not yet scored
      • Built and inspected by Glamanot measured
        never built and inspected by Glama
    • Trust100 / 100 · weight 9%
      • License100
      • Published by the vendor it integratesnot measured
        not published by the vendor it integrates
    Weighted mean of the five
    66.6
    × relevance: the keyword is dedicated here
    1.00
    × continuity: actively changing
    1.00
    × evidence: modest but real audience
    0.85
    Composite score
    56.6
  • 9

    GitMCP

    Abandoned but popular▼ 1
    idosal/git-mcp ↗

    Best for: AI assistants needing current documentation and code for a specific GitHub repository: it exposes remote MCP endpoints such as gitmcp.io/{owner}/{repo} and gitmcp.io/docs.

    GitMCP exposes 32 tools for Git operations, Gitea and GitHub repository management, authentication, configuration, releases, versioning, backups, and health checks, while its README documents remote MCP endpoints that turn GitHub repositories or GitHub Pages sites into documentation sources. Before choosing it, note that the documented hosted setup requires adding a GitMCP URL such as gitmcp.io/{owner}/{repo} or gitmcp.io/docs as an MCP server in an AI assistant or IDE.

    GitHub stars
    8,417
    Stars over the last 90 days: 8,231 at the earliest of 9 readings and 8,417 at the latest, up 186.
    Stars / 30 days
    +76
    npm / typical week
    downloads not counted
    PyPI / typical week
    no attributed package
    Tools exposed
    32
    Last commit
    142 days ago
    Commits / 12 weeks
    0
    Maintenance grade
    F
    Tool descriptions
    C
    Score 56.3: show every number behind it
    • Adoption98 / 100 · weight 40%
      • GitHub stars98
      • npm downloadsnot measured
        npm names no repository for git-mcp, so its downloads cannot be attributed
      • Used through Glamanot measured
        not used through Glama in the last 30 days
    • Maintenance40 / 100 · weight 24%
      • Last commit touching this server68
      • Repository maintenance grade5
      • Commit cadence5
    • Momentum54 / 100 · weight 14%
      • Stars gained, relative to size38
      • Stars gained, absolute76
      • npm download trendnot measured
        no download history for the selected registry
    • Tool quality53 / 100 · weight 13%
      • Tool description quality45
      • Built and inspected by Glama100
    • Trust100 / 100 · weight 9%
      • License100
      • Published by the vendor it integratesnot measured
        not published by the vendor it integrates
    Weighted mean of the five
    72.2
    × relevance: the keyword is declared here
    0.78
    × continuity: actively changing
    1.00
    × evidence: widely adopted
    1.00
    Composite score
    56.3
  • 10

    cve-mcp

    Community favouriteNo change
    badchars/cve-mcp ↗

    Best for: Incident response and dependency triage on a known CVE list: 41 tools pull NVD, EPSS, KEV and OSV data and rank vulnerabilities by exploitation risk.

    cve-mcp exposes 41 tools that query NVD, EPSS, CISA KEV, GitHub Advisory, OSV, Shodan, VulnCheck, Vulners, Nuclei, Metasploit, CIRCL and AttackerKB for CVE lookup, package and CPE matching, exploit and weaponization checks, and CVE prioritization, comparison and enrichment. Before choosing it, note that it is distributed as an npm package whose README badges Bun as the runtime, and that some of the aggregated sources accept optional API keys, with a source-status tool reporting which keys are configured.

    GitHub stars
    28
    Stars over the last 90 days: 12 at the earliest of 11 readings and 29 at the latest, up 17.
    Stars / 30 days
    +11
    npm / typical week
    385
    PyPI / typical week
    no attributed package
    Tools exposed
    41
    Last commit
    83 days ago
    Commits / 12 weeks
    3
    Maintenance grade
    B
    Tool descriptions
    A
    Score 54.4: show every number behind it
    • Adoption61 / 100 · weight 40%
      • GitHub stars37
      • npm downloads55
      • Used through Glamanot measured
        not used through Glama in the last 30 days
    • Maintenance76 / 100 · weight 24%
      • Last commit touching this server88
        dated from the last commit on the default branch, re-read from GitHub at publication; github.com shows a push 11 days ago, which counts every ref; the stored date would have published 11 days ago
      • Repository maintenance grade80
      • Commit cadence40
    • Momentum60 / 100 · weight 14%
      • Stars gained, relative to size100
      • Stars gained, absolute43
      • npm download trend8
    • Tool quality76 / 100 · weight 13%
      • Tool description quality68
      • Built and inspected by Glama100
    • Trust100 / 100 · weight 9%
      • License100
      • Published by the vendor it integratesnot measured
        not published by the vendor it integrates
    Weighted mean of the five
    69.7
    × relevance: the keyword is declared here
    0.78
    × continuity: actively changing
    1.00
    × evidence: widely adopted
    1.00
    Composite score
    54.4
  • 11

    Best for: Preparing AI skills or RAG knowledge from mixed sources: it scrapes GitHub repos, docs sites, PDFs, and videos and exports to vector databases.

    Skill Seekers exposes 40 MCP tools that scrape documentation sites, GitHub repositories, PDFs, videos, notebooks, wikis, and local codebases into packaged Claude, Gemini, or OpenAI skills, or into vector-database exports. It assumes Python 3.10 or newer and installation from PyPI as skill-seekers, with the MCP server added through the skill-seekers[mcp] extra.

    GitHub stars
    15,020
    Stars over the last 90 days: 14,342 at the earliest of 15 readings and 15,020 at the latest, up 678.
    Stars / 30 days
    +213
    npm / typical week
    Ships no npm package
    PyPI / typical week
    3.7K
    skill-seekers
    Tools exposed
    40
    Last commit
    7 days ago
    Commits / 12 weeks
    108
    Weekly commits over the last 12 weeks, oldest first: 2, 0, 17, 0, 25, 1, 0, 0, 19, 0, 31, 13. 108 in total, and the last figure is the current week so far.
    Maintenance grade
    A
    Tool descriptions
    B
    Score 52.9: show every number behind it
    • Adoption100 / 100 · weight 40%
      • GitHub stars100
      • PyPI downloads38
        PyPI downloads show no weekday rhythm; halved
      • Used through Glamanot measured
        not used through Glama in the last 30 days
    • Maintenance100 / 100 · weight 24%
      • Last commit touching this server100
      • Repository maintenance grade100
      • Commit cadence100
    • Momentum52 / 100 · weight 14%
      • Stars gained, relative to size49
      • Stars gained, absolute94
      • PyPI download trend9
    • Tool quality61 / 100 · weight 13%
      • Tool description quality53
      • Built and inspected by Glama100
    • Trust100 / 100 · weight 9%
      • License100
      • Published by the vendor it integratesnot measured
        not published by the vendor it integrates
    Weighted mean of the five
    88.2
    × relevance: the keyword is tagged here
    0.60
    × continuity: actively changing
    1.00
    × evidence: widely adopted
    1.00
    Composite score
    52.9
  • 12

    mcp-skylos

    Community favouriteNo change
    duriantaco/skylos ↗

    Best for: Static analysis before merge in an MCP-compatible coding agent: it exposes twelve tools for dead code, security, secrets, quality, and diff validation.

    mcp-skylos is an MCP server that exposes twelve static-analysis tools, including analyze, security_scan, secrets_scan, quality_check, and validate_code_change, and returns findings with file paths, line numbers, and severity. Its MCP description names Python, TypeScript, and Go as scan targets, while the README documents a broader CLI language list.

    GitHub stars
    836
    Stars over the last 90 days: 464 at the earliest of 41 readings and 836 at the latest, up 372.
    Stars / 30 days
    +381
    npm / typical week
    Ships no npm package
    PyPI / typical week
    16.3K
    skylos
    Tools exposed
    12
    Last commit
    today
    Commits / 12 weeks
    173
    Weekly commits over the last 12 weeks, oldest first: 7, 3, 6, 25, 12, 10, 13, 18, 5, 30, 29, 15. 173 in total, and the last figure is the current week so far.
    Maintenance grade
    A
    Tool descriptions
    D
    Score 52.8: show every number behind it
    • Adoption100 / 100 · weight 40%
      • GitHub stars73
      • PyPI downloads90
      • Used through Glamanot measured
        not used through Glama in the last 30 days
    • Maintenance100 / 100 · weight 24%
      • Last commit touching this server100
      • Repository maintenance grade100
      • Commit cadence100
    • Momentum81 / 100 · weight 14%
      • Stars gained, relative to size100
      • Stars gained, absolute100
      • PyPI download trend23
    • Tool quality28 / 100 · weight 13%
      • Tool description quality20
      • Built and inspected by Glama100
    • Trust100 / 100 · weight 9%
      • License100
      • Published by the vendor it integratesnot measured
        not published by the vendor it integrates
    Weighted mean of the five
    88.0
    × relevance: the keyword is tagged here
    0.60
    × continuity: actively changing
    1.00
    × evidence: widely adopted
    1.00
    Composite score
    52.8
  • 13

    pipelock

    Community favourite▲ 1
    luckyPipewrench/pipelock ↗

    Best for: Securing an agent that calls MCP servers with secrets: it proxies MCP traffic and scans bidirectionally for credential leaks, prompt injection, and tool description poisoning.

    Pipelock is a security proxy that wraps any MCP server and inspects mediated HTTP, WebSocket, MCP, and A2A traffic, scanning bidirectionally for credential leaks, prompt injection, and tool description poisoning. Before choosing it, know that no npm package is published and no PyPI package is attributed, and CONNECT tunnel content scanning requires TLS interception, so setup is not a package-manager one-liner.

    GitHub stars
    905
    Stars over the last 90 days: 740 at the earliest of 59 readings and 905 at the latest, up 165.
    Stars / 30 days
    +101
    npm / typical week
    Ships no npm package
    PyPI / typical week
    no attributed package
    Tools exposed
    never inspected
    Last commit
    today
    Commits / 12 weeks
    755
    Weekly commits over the last 12 weeks, oldest first: 77, 51, 65, 45, 49, 63, 47, 76, 72, 74, 75, 61. 755 in total, and the last figure is the current week so far.
    Maintenance grade
    A
    Tool descriptions
    Not graded
    Score 50.6: show every number behind it
    • Adoption74 / 100 · weight 40%
      • GitHub stars74
      • npm downloadsnot measured
        no npm package
      • Used through Glamanot measured
        not used through Glama in the last 30 days
    • Maintenance100 / 100 · weight 24%
      • Last commit touching this server100
      • Repository maintenance grade100
      • Commit cadence100
    • Momentum92 / 100 · weight 14%
      • Stars gained, relative to size100
      • Stars gained, absolute81
      • npm download trendnot measured
        no download history for the selected registry
    • Tool quality≈68 / 100 · weight 13%
      • Tool description quality≈68
        tool descriptions not yet scored
      • Built and inspected by Glamanot measured
        never built and inspected by Glama
    • Trust100 / 100 · weight 9%
      • License100
      • Published by the vendor it integratesnot measured
        not published by the vendor it integrates
    Weighted mean of the five
    84.3
    × relevance: the keyword is tagged here
    0.60
    × continuity: actively changing
    1.00
    × evidence: widely adopted
    1.00
    Composite score
    50.6
  • 14

    Loki Mode

    Community favourite▲ 1
    asklokesh/loki-mode ↗

    Best for: Autonomous spec-driven builds inside a repository, where the MCP client needs project state, task-queue, memory, code-search, and verification tools over stdio.

    Loki Mode is an autonomous spec-to-product coding-agent CLI whose MCP server is described as exposing stdio tools for project state, task queues, memory, code search, quality and verification reports, repository hotspots and co-changes, and structured findings. The thing to know before choosing it is that the Claude Code plugin assumes the loki-mode CLI is already installed, because the plugin calls the CLI rather than bundling it.

    GitHub stars
    1,072
    Stars over the last 90 days: 1,000 at the earliest of 42 readings and 1,072 at the latest, up 72.
    Stars / 30 days
    +22
    npm / typical week
    2.1K
    PyPI / typical week
    no attributed package
    Tools exposed
    never inspected
    Last commit
    today
    Commits / 12 weeks
    929
    Weekly commits over the last 12 weeks, oldest first: 38, 77, 16, 160, 314, 125, 32, 25, 3, 47, 74, 18. 929 in total, and the last figure is the current week so far.
    Maintenance grade
    A
    Tool descriptions
    Not graded
    Score 49.2: show every number behind it
    • Adoption86 / 100 · weight 40%
      • GitHub stars76
      • npm downloads71
      • Used through Glamanot measured
        not used through Glama in the last 30 days
    • Maintenance100 / 100 · weight 24%
      • Last commit touching this server100
      • Repository maintenance grade100
      • Commit cadence100
    • Momentum41 / 100 · weight 14%
      • Stars gained, relative to size55
      • Stars gained, absolute55
      • npm download trend0
    • Tool quality≈68 / 100 · weight 13%
      • Tool description quality≈68
        tool descriptions not yet scored
      • Built and inspected by Glamanot measured
        never built and inspected by Glama
    • Trust100 / 100 · weight 9%
      • License100
      • Published by the vendor it integratesnot measured
        not published by the vendor it integrates
    Weighted mean of the five
    82.0
    × relevance: the keyword is tagged here
    0.60
    × continuity: actively changing
    1.00
    × evidence: widely adopted
    1.00
    Composite score
    49.2
  • Best for: Teams automating GitHub Actions, pull requests, code search, and repository management from an MCP client: it documents compact, JSON, and Markdown response formats.

    Its README documents GitHub workflow automation for Actions monitoring, pull request management, code search, file operations, and repository management, with compact, JSON, and Markdown response formats and a code-first mode enabled by default. Before choosing it, note that its tool list has not been inspected, so the advertised tool count cannot be confirmed; installation assumes Python 3.10+ and the PyPI package github-mcp-server, with no npm package published.

    GitHub stars
    5
    Stars over the last 90 days: 4 at the earliest of 10 readings and 5 at the latest, up 1.
    Stars / 30 days
    +1
    npm / typical week
    Ships no npm package
    PyPI / typical week
    102
    github-mcp-server
    Tools exposed
    never inspected
    Last commit
    61 days ago
    Commits / 12 weeks
    1
    Weekly commits over the last 12 weeks, oldest first: 0, 0, 0, 1, 0, 0, 0, 0, 0, 0, 0, 0. 1 in total, and the last figure is the current week so far.
    Maintenance grade
    B
    Tool descriptions
    Not graded
    Score 49.2: show every number behind it
    • Adoption46 / 100 · weight 40%
      • GitHub stars19
      • PyPI downloads43
      • Used through Glamanot measured
        not used through Glama in the last 30 days
    • Maintenance76 / 100 · weight 24%
      • Last commit touching this server88
      • Repository maintenance grade80
      • Commit cadence40
    • Momentum25 / 100 · weight 14%
      • Stars gained, relative to size39
      • Stars gained, absolute16
      • PyPI download trend11
    • Tool quality≈68 / 100 · weight 13%
      • Tool description quality≈68
        tool descriptions not yet scored
      • Built and inspected by Glamanot measured
        never built and inspected by Glama
    • Trust100 / 100 · weight 9%
      • License100
      • Published by the vendor it integratesnot measured
        not published by the vendor it integrates
    Weighted mean of the five
    57.9
    × relevance: the keyword is dedicated here
    1.00
    × continuity: actively changing
    1.00
    × evidence: modest but real audience
    0.85
    Composite score
    49.2
  • Best for: Running authorized coding, bug-fixing, tests or refactors in Claude Code or Cursor while capping session spend: it enforces budgets, preflight validation and verifier safety gates.

    MartinLoop exposes 24 MCP tools for governed coding runs, including planning with martin_plan, preflight validation, execution via martin_run, budget and stop-pressure checks, run dossiers, verification results, and GitHub PR creation with martin_create_pr. Before choosing it, note that completion requires fresh verifier evidence bound to the active run and workspace, so a VERIFIED result does not claim the code is bug-free or automatically safe to merge.

    GitHub stars
    192
    Stars over the last 90 days: 39 at the earliest of 24 readings and 192 at the latest, up 153.
    Stars / 30 days
    +181
    npm / typical week
    217
    PyPI / typical week
    no attributed package
    Tools exposed
    24
    Last commit
    today
    Commits / 12 weeks
    441
    Weekly commits over the last 12 weeks, oldest first: 13, 30, 22, 18, 0, 11, 143, 43, 23, 70, 44, 24. 441 in total, and the last figure is the current week so far.
    Maintenance grade
    A
    Tool descriptions
    A
    Score 47.8: show every number behind it
    • Adoption61 / 100 · weight 40%
      • GitHub stars57
      • npm downloads25
        downloads show none of the weekday rhythm human traffic has; halved
      • Used through Glamanot measured
        not used through Glama in the last 30 days
    • Maintenance100 / 100 · weight 24%
      • Last commit touching this server100
      • Repository maintenance grade100
      • Commit cadence100
    • Momentum90 / 100 · weight 14%
      • Stars gained, relative to size100
      • Stars gained, absolute91
      • npm download trend69
    • Tool quality76 / 100 · weight 13%
      • Tool description quality68
      • Built and inspected by Glama100
    • Trust100 / 100 · weight 9%
      • License100
      • Published by the vendor it integratesnot measured
        not published by the vendor it integrates
    Weighted mean of the five
    79.7
    × relevance: the keyword is tagged here
    0.60
    × continuity: actively changing
    1.00
    × evidence: widely adopted
    1.00
    Composite score
    47.8
  • Best for: Auditing a GitHub org's security posture from an AI agent: 39 tools across org settings, repository config, workflows, secrets, supply chain and access control.

    The server exposes 39 tools that call GitHub APIs to inspect organization settings such as 2FA enforcement and SSO, repository configuration including branch protection, secret scanning, code scanning and Dependabot, Actions workflow risks such as script injection and unpinned actions, secret and supply chain coverage, and team, collaborator, GitHub App and PAT access, with aggregation and markdown report tools over the findings collected in a session. Before installing, note that it runs on Bun and expects a GITHUB_TOKEN carrying repo, admin:org, admin:org_hook and admin:repo_hook scopes, with Enterprise-only features handled by graceful degradation rather than full coverage through the public API.

    GitHub stars
    13
    Stars over the last 90 days: 9 at the earliest of 10 readings and 14 at the latest, up 5.
    Stars / 30 days
    +1
    npm / typical week
    207
    PyPI / typical week
    no attributed package
    Tools exposed
    39
    Last commit
    197 days ago
    Commits / 12 weeks
    0
    Maintenance grade
    D
    Tool descriptions
    A
    Score 46.2: show every number behind it
    • Adoption54 / 100 · weight 40%
      • GitHub stars29
      • npm downloads49
      • Used through Glamanot measured
        not used through Glama in the last 30 days
    • Maintenance46 / 100 · weight 24%
      • Last commit touching this server68
      • Repository maintenance grade30
      • Commit cadence5
    • Momentum22 / 100 · weight 14%
      • Stars gained, relative to size38
      • Stars gained, absolute16
      • npm download trend0
    • Tool quality76 / 100 · weight 13%
      • Tool description quality68
      • Built and inspected by Glama100
    • Trust100 / 100 · weight 9%
      • License100
      • Published by the vendor it integratesnot measured
        not published by the vendor it integrates
    Weighted mean of the five
    54.4
    × relevance: the keyword is dedicated here
    1.00
    × continuity: actively changing
    1.00
    × evidence: modest but real audience
    0.85
    Composite score
    46.2
  • 18

    Node9-Proxy

    Community favourite▼ 1
    node9-ai/node9-proxy ↗

    Best for: Securing GitHub-connected agents that run with permissions skipped: it hooks every tool call, blocking credential-file reads and holding destructive git or shell actions for review.

    Node9-Proxy is a hook-based gate for MCP tool calls, with its README documenting a credential jail, approval holds for destructive git, SQL and shell actions, MCP tool pinning, a network egress allowlist, a loop breaker, and audit logging across agents. Choosing it requires Node.js 22+ and a node9 init run in each project to install the hooks; the README presents it as governing other agents and MCP servers rather than exposing its own GitHub tool set.

    GitHub stars
    216
    Stars over the last 90 days: 207 at the earliest of 36 readings and 216 at the latest, up 9.
    Stars / 30 days
    +8
    npm / typical week
    1.2K
    PyPI / typical week
    no attributed package
    Tools exposed
    never inspected
    Last commit
    today
    Commits / 12 weeks
    707
    Weekly commits over the last 12 weeks, oldest first: 76, 53, 48, 16, 0, 17, 42, 39, 102, 96, 73, 145. 707 in total, and the last figure is the current week so far.
    Maintenance grade
    A
    Tool descriptions
    Not graded
    Score 45.7: show every number behind it
    • Adoption63 / 100 · weight 40%
      • GitHub stars58
      • npm downloads33
        downloads show none of the weekday rhythm human traffic has; halved
      • Used through Glamanot measured
        not used through Glama in the last 30 days
    • Maintenance100 / 100 · weight 24%
      • Last commit touching this server100
      • Repository maintenance grade100
      • Commit cadence100
    • Momentum64 / 100 · weight 14%
      • Stars gained, relative to size62
      • Stars gained, absolute39
      • npm download trend100
    • Tool quality≈68 / 100 · weight 13%
      • Tool description quality≈68
        tool descriptions not yet scored
      • Built and inspected by Glamanot measured
        never built and inspected by Glama
    • Trust100 / 100 · weight 9%
      • License100
      • Published by the vendor it integratesnot measured
        not published by the vendor it integrates
    Weighted mean of the five
    76.2
    × relevance: the keyword is tagged here
    0.60
    × continuity: actively changing
    1.00
    × evidence: widely adopted
    1.00
    Composite score
    45.7
  • Best for: Managing AI personas and other reusable elements in a local portfolio: it exposes five tools spanning create, read, update, delete and execute.

    DollhouseMCP exposes five tools (create, read, update, delete, execute) that manage personas, skills, templates, agents, memories and ensembles held in a local portfolio folder, with community sharing and GitHub sync. Its README states that permission hook support is full only on Claude Code and that Claude Desktop has no native permission hook path in this release, so the confirmation and agentic loop features depend on which client it is installed into.

    GitHub stars
    44
    Stars over the last 90 days: 35 at the earliest of 32 readings and 44 at the latest, up 9.
    Stars / 30 days
    +4
    npm / typical week
    301
    PyPI / typical week
    no attributed package
    Tools exposed
    5
    Last commit
    6 days ago
    Commits / 12 weeks
    128
    Weekly commits over the last 12 weeks, oldest first: 0, 0, 0, 8, 59, 0, 0, 27, 11, 0, 0, 23. 128 in total, and the last figure is the current week so far.
    Maintenance grade
    B
    Tool descriptions
    A
    Score 44.5: show every number behind it
    • Adoption45 / 100 · weight 40%
      • GitHub stars41
      • npm downloads26
        downloads show none of the weekday rhythm human traffic has; halved
      • Used through Glama14
    • Maintenance95 / 100 · weight 24%
      • Last commit touching this server100
      • Repository maintenance grade80
      • Commit cadence100
    • Momentum37 / 100 · weight 14%
      • Stars gained, relative to size60
      • Stars gained, absolute29
      • npm download trend4
    • Tool quality93 / 100 · weight 13%
      • Tool description quality85
      • Built and inspected by Glama100
    • Trust100 / 100 · weight 9%
      • License100
      • Published by the vendor it integratesnot measured
        not published by the vendor it integrates
    Weighted mean of the five
    67.1
    × relevance: the keyword is declared here
    0.78
    × continuity: actively changing
    1.00
    × evidence: modest but real audience
    0.85
    Composite score
    44.5
  • Best for: Summarizing a GitHub organization's issues, discussions, and pull requests beyond the standard API item limit: it stores data locally and returns token-efficient Markdown.

    GitHub Brain MCP Server summarizes discussions, issues, and pull requests from a local database populated through its interactive TUI, and its README documents a stdio MCP server started with github-brain mcp for Claude and VS Code. Before adoption, note that the MCP server requires a GitHub organization via -o or ORGANIZATION, reads only from the local database after a Pull, and complements rather than replaces the official GitHub MCP server.

    GitHub stars
    78
    Stars over the last 90 days: 78 at the earliest of 10 readings and 78 at the latest, unchanged.
    Stars / 30 days
    0
    npm / typical week
    14
    PyPI / typical week
    no attributed package
    Tools exposed
    never inspected
    Last commit
    235 days ago
    Commits / 12 weeks
    0
    Maintenance grade
    C
    Tool descriptions
    Not graded
    Score 43.8: show every number behind it
    • Adoption49 / 100 · weight 40%
      • GitHub stars47
      • npm downloads13
        downloads show none of the weekday rhythm human traffic has; halved
      • Used through Glamanot measured
        not used through Glama in the last 30 days
    • Maintenance52 / 100 · weight 24%
      • Last commit touching this server68
      • Repository maintenance grade55
      • Commit cadence5
    • Momentum11 / 100 · weight 14%
      • Stars gained, relative to size0
      • Stars gained, absolute0
      • npm download trend44
    • Tool quality≈68 / 100 · weight 13%
      • Tool description quality≈68
        tool descriptions not yet scored
      • Built and inspected by Glamanot measured
        never built and inspected by Glama
    • Trust100 / 100 · weight 9%
      • License100
      • Published by the vendor it integratesnot measured
        not published by the vendor it integrates
    Weighted mean of the five
    51.5
    × relevance: the keyword is dedicated here
    1.00
    × continuity: actively changing
    1.00
    × evidence: modest but real audience
    0.85
    Composite score
    43.8

Questions people ask

What does GitHub MCP Server require before it will run?

GitHub MCP Server (github/github-mcp-server) installs as a remote HTTP MCP server at api.githubcopilot.com/mcp/ using OAuth or a PAT. The evidence above lists no npm package published and no PyPI package attributed for it, so the setup described is the remote endpoint rather than a local package install. Its default branch had a commit 11 days ago and 184 commits in the last 12 weeks.

What should I be careful about when using github-security-mcp?

github-security-mcp (badchars/github-security-mcp) is labeled Dormant, and its default branch had a commit 197 days ago with 0 commits in the last 12 weeks. It exposes 39 tools across org settings, repository config, workflows, secrets, supply chain, and access control, and its tool descriptions are graded A. If you need active maintenance, check that record before pointing an agent at it for security audits.

Which server should I use for GitHub Projects V2 tracking?

Use mcp-github-project-manager (kunwarVivek/mcp-github-project-manager). It exposes 84 tools covering roadmaps, milestones, sprint metrics, draft issues, and pull request reviews, and its default branch had a commit 5 days ago with 81 commits in the last 12 weeks. Its tool descriptions are graded C, so expect weaker tool descriptions than servers graded A.

Can GitMCP still work for current repository documentation?

GitMCP (idosal/git-mcp) exposes remote MCP endpoints such as gitmcp.io/{owner}/{repo} and gitmcp.io/docs, and it has 8,417 GitHub stars. It is labeled Abandoned but popular, its default branch had a commit 142 days ago, and it has 0 commits in the last 12 weeks. It also exposes 32 tools with tool descriptions graded C.

How do I secure an agent that calls GitHub MCP servers with secrets?

Use pipelock (luckyPipewrench/pipelock), which proxies MCP traffic and scans bidirectionally for credential leaks, prompt injection, and tool description poisoning. It had a commit 0 days ago and 755 commits in the last 12 weeks. Node9-Proxy (node9-ai/node9-proxy) is another option: it hooks every tool call, blocking credential-file reads and holding destructive git or shell actions for review, and @node9/proxy had 1,180 npm downloads in a typical week.

Other comparisons