20 Best GitHub MCP Servers, Compared (October 2026)
The short answer
For most readers, the server to reach for is GitHub MCP Server (github/github-mcp-server). It is GitHub's official MCP Server, has 33,210 GitHub stars and 696 stars gained per 30 days, and its default branch had a commit 11 days ago with 184 commits in the last 12 weeks. It is designed to connect an AI assistant to GitHub in VS Code as a remote HTTP MCP server at api.githubcopilot.com/mcp/ using OAuth or a PAT. If your task is retrieving specific code symbols from an indexed repository instead of general GitHub access, github-codemunch-mcp (jgravelle/jcodemunch-mcp) is the better answer: it exposes 7 tools, its tool descriptions are graded A, and its default branch had a commit 0 days ago.
Whichever you choose, give it the narrowest access that still works (a read-only credential, a replica, a scratch account), and widen it only once you have watched what your agent actually asks for.
Glama operates the MCP registry these numbers are measured from, and sells MCP hosting and a gateway. No position on this page is paid for. How the registry is built.
Quick picks
- 1GitHub MCP Server : Connecting an AI assistant to GitHub in VS Code: it installs as a remote HTTP MCP server at api.githubcopilot.com/mcp/ using OAuth or a PAT.
- 2github-codemunch-mcp : Retrieving specific code symbols from an indexed repository: it exposes seven tools for tree-sitter indexing, file outlines, symbol search, and exact source retrieval.
- 3Octocode MCP : Researching code across GitHub repositories and local checkouts in one session: it pairs GitHub search, file, and pull request tools with local ripgrep, filesystem, and LSP tools.
- 4mcp-github-project-manager : Sprint and milestone tracking on GitHub Projects V2: it exposes 84 tools covering roadmaps, milestones, sprint metrics, draft issues, and pull request reviews.
- 5idea-reality-mcp : Before building a product idea: it exposes idea_check to check whether that idea already exists.
Which one, for your situation
| Your situation | What to use |
|---|---|
| Connecting an AI assistant to GitHub in VS Code | Use GitHub MCP Server (github/github-mcp-server), which installs as a remote HTTP MCP server at api.githubcopilot.com/mcp/ using OAuth or a PAT. |
| Fetching exact code symbols from an indexed repository | Use github-codemunch-mcp (jgravelle/jcodemunch-mcp), which exposes 7 tools for tree-sitter indexing, file outlines, symbol search, and exact source retrieval and had a commit 0 days ago. |
| Tracking sprints and milestones on GitHub Projects V2 | Use mcp-github-project-manager (kunwarVivek/mcp-github-project-manager), which exposes 84 tools for roadmaps, milestones, sprint metrics, draft issues, and pull request reviews. |
| Checking whether a product idea already exists | Use idea-reality-mcp (mnemox-ai/idea-reality-mcp), which exposes idea_check to check whether that idea already exists and had a commit 9 days ago. |
| Auditing a GitHub org's security posture | Use github-security-mcp (badchars/github-security-mcp), which exposes 39 tools across org settings, repository config, workflows, secrets, supply chain, and access control, but note its default branch had a commit 197 days ago. |
| Securing an agent that calls MCP servers with secrets | Use pipelock (luckyPipewrench/pipelock), which proxies MCP traffic and scans bidirectionally for credential leaks, prompt injection, and tool description poisoning. |
Top MCP servers for GitHub
| Best for | Profile | ||||||
|---|---|---|---|---|---|---|---|
| 1 | Connecting an AI assistant to GitHub in VS Code: it installs as a remote HTTP MCP server at api.githubcopilot.com/mcp/ using OAuth or a PAT. | Community favourite | 33,210 | +696 | 11 days ago | 92.4 | |
| 2 | Retrieving specific code symbols from an indexed repository: it exposes seven tools for tree-sitter indexing, file outlines, symbol search, and exact source retrieval. | Community favourite | 2,715 | +87 | today | 78.7 | |
| 3 | Researching code across GitHub repositories and local checkouts in one session: it pairs GitHub search, file, and pull request tools with local ripgrep, filesystem, and LSP tools. | Community favourite | 944 | +28 | 33 days ago | 67.9 | |
| 4 | Sprint and milestone tracking on GitHub Projects V2: it exposes 84 tools covering roadmaps, milestones, sprint metrics, draft issues, and pull request reviews. | Steady | 101 | +9 | 5 days ago | 67.5 | |
| 5 | Before building a product idea: it exposes idea_check to check whether that idea already exists. | Community favourite | 821 | +19 | 9 days ago | 61.9 | |
| 6 | Debugging a library or cloud error and needing StackOverflow or GitHub Issue answers, not snippets: it returns full conversations and structured content in one call. | Community favourite | 395 | +18 | today | 60.0 | |
| 7 | Preventing duplicate code before committing: it exposes check_duplication, get_file_clones, get_statistics, and check_current_directory against the scanned project. | Community favourite | 6,273 | +181 | today | 56.9 | |
| 8 | Finding a previously starred repository by description rather than keyword: it exposes a natural language search tool backed by Cloudflare AutoRAG over repository READMEs. | Steady | 116 | +4 | yesterday | 56.6 | |
| 9 | AI assistants needing current documentation and code for a specific GitHub repository: it exposes remote MCP endpoints such as gitmcp.io/{owner}/{repo} and gitmcp.io/docs. | Abandoned but popular | 8,417 | +76 | 142 days ago | 56.3 | |
| 10 | Incident response and dependency triage on a known CVE list: 41 tools pull NVD, EPSS, KEV and OSV data and rank vulnerabilities by exploitation risk. | Community favourite | 28 | +11 | 83 days ago | 54.4 | |
| 11 | Preparing AI skills or RAG knowledge from mixed sources: it scrapes GitHub repos, docs sites, PDFs, and videos and exports to vector databases. | Community favourite | 15,020 | +213 | 7 days ago | 52.9 | |
| 12 | Static analysis before merge in an MCP-compatible coding agent: it exposes twelve tools for dead code, security, secrets, quality, and diff validation. | Community favourite | 836 | +381 | today | 52.8 | |
| 13 | Securing an agent that calls MCP servers with secrets: it proxies MCP traffic and scans bidirectionally for credential leaks, prompt injection, and tool description poisoning. | Community favourite | 905 | +101 | today | 50.6 | |
| 14 | Autonomous spec-driven builds inside a repository, where the MCP client needs project state, task-queue, memory, code-search, and verification tools over stdio. | Community favourite | 1,072 | +22 | today | 49.2 | |
| 15 | Teams automating GitHub Actions, pull requests, code search, and repository management from an MCP client: it documents compact, JSON, and Markdown response formats. | Steady | 5 | +1 | 61 days ago | 49.2 | |
| 16 | Running authorized coding, bug-fixing, tests or refactors in Claude Code or Cursor while capping session spend: it enforces budgets, preflight validation and verifier safety gates. | Community favourite | 192 | +181 | today | 47.8 | |
| 17 | Auditing a GitHub org's security posture from an AI agent: 39 tools across org settings, repository config, workflows, secrets, supply chain and access control. | Dormant | 13 | +1 | 197 days ago | 46.2 | |
| 18 | Securing GitHub-connected agents that run with permissions skipped: it hooks every tool call, blocking credential-file reads and holding destructive git or shell actions for review. | Community favourite | 216 | +8 | today | 45.7 | |
| 19 | Managing AI personas and other reusable elements in a local portfolio: it exposes five tools spanning create, read, update, delete and execute. | Steady | 44 | +4 | 6 days ago | 44.5 | |
| 20 | Summarizing a GitHub organization's issues, discussions, and pull requests beyond the standard API item limit: it stores data locally and returns token-efficient Markdown. | Dormant | 78 | 0 | 235 days ago | 43.8 |
The ranking, with the evidence
Each position is a weighted mean of adoption (40%), maintenance (24%), momentum (14%), tool description quality (13%) and trust (9%), multiplied by three attenuators: how directly the server is about GitHub (named for it, declaring it, tagged with it, or merely mentioning it), whether its repository is still moving, and how much independent evidence of adoption it has. Open the score on any entry to see every number, including the ones marked ≈, which were imputed from the median of the other candidates rather than measured. The maintenance grade on each entry is mostly issue responsiveness, release recency and open security alerts rather than commits, so a recent commit beside a low grade is two different measurements rather than a contradiction.
- Abandoned but popular: People use it, but its default branch has stopped moving. Fine to keep running, risky to adopt.
- Community favourite: Widely adopted and still actively maintained.
- Dormant: Neither changing nor widely adopted. Here because it still matches the search.
- Emerging: Small audience, growing quickly, maintained. The bet with the most upside.
- Steady: Maintained, modest audience, no surprises in either direction.
Best for: Connecting an AI assistant to GitHub in VS Code: it installs as a remote HTTP MCP server at api.githubcopilot.com/mcp/ using OAuth or a PAT.
The GitHub MCP Server provides GitHub access through a remote HTTP MCP endpoint at api.githubcopilot.com/mcp/ with OAuth or PAT authentication, plus a local version for hosts without remote support. Before choosing it, note that the remote server requires a compatible MCP host with remote server support and any applicable policies enabled.
GitHub stars33,210Stars / 30 days+696npm / typical weekShips no npm packagePyPI / typical weekno attributed packageTools exposednever inspectedLast commit11 days agoCommits / 12 weeks184Maintenance gradeATool descriptionsNot gradedScore 92.4: show every number behind it
- Adoption100 / 100 · weight 40%
- GitHub stars100
- npm downloadsnot measuredno npm package
- Used through Glamanot measurednot used through Glama in the last 30 days
- Maintenance100 / 100 · weight 24%
- Last commit touching this server100
- Repository maintenance grade100
- Commit cadence100
- Momentum76 / 100 · weight 14%
- Stars gained, relative to size59
- Stars gained, absolute100
- npm download trendnot measuredno download history for the selected registry
- Tool quality≈68 / 100 · weight 13%
- Tool description quality≈68tool descriptions not yet scored
- Built and inspected by Glamanot measurednever built and inspected by Glama
- Trust100 / 100 · weight 9%
- License100
- Published by the vendor it integrates100
- Weighted mean of the five
- 92.4
- × relevance: the keyword is dedicated here
- 1.00
- × continuity: actively changing
- 1.00
- × evidence: widely adopted
- 1.00
- Composite score
- 92.4
Best for: Retrieving specific code symbols from an indexed repository: it exposes seven tools for tree-sitter indexing, file outlines, symbol search, and exact source retrieval.
github-codemunch-mcp indexes a GitHub repository's source code locally, parsing it with tree-sitter to store symbol signatures and summaries, and it exposes seven tools for listing indexed repos, viewing file trees and outlines, searching symbols, and fetching one or more symbol sources. Before choosing it, note that it requires an indexing step per repository (index_repo) and keeps that index in local storage, so it covers exploration and retrieval of already indexed code rather than editing repositories or querying them without an index.
GitHub stars2,715Stars / 30 days+87npm / typical weekShips no npm packagePyPI / typical week17.8Kjcodemunch-mcpTools exposed7Last committodayCommits / 12 weeks1,049Maintenance gradeATool descriptionsAScore 78.7: show every number behind it
- Adoption93 / 100 · weight 40%
- GitHub stars86
- PyPI downloads45PyPI downloads show no weekday rhythm; halved
- Used through Glamanot measurednot used through Glama in the last 30 days
- Maintenance100 / 100 · weight 24%
- Last commit touching this server100
- Repository maintenance grade100
- Commit cadence100
- Momentum56 / 100 · weight 14%
- Stars gained, relative to size72
- Stars gained, absolute78
- PyPI download trend0
- Tool quality76 / 100 · weight 13%
- Tool description quality68
- Built and inspected by Glama100
- Trust0 / 100 · weight 9%
- License0
- Published by the vendor it integratesnot measurednot published by the vendor it integrates
- Weighted mean of the five
- 78.7
- × relevance: the keyword is dedicated here
- 1.00
- × continuity: actively changing
- 1.00
- × evidence: widely adopted
- 1.00
- Composite score
- 78.7
Best for: Researching code across GitHub repositories and local checkouts in one session: it pairs GitHub search, file, and pull request tools with local ripgrep, filesystem, and LSP tools.
Octocode MCP exposes 13 tools split between GitHub API operations (code, repository, and pull request search, file reads, repo structure), local work over ripgrep, filesystem, and LSP, and npm/PyPI package lookup, and the README documents the same set running either as an MCP server or as a CLI. The LSP tools require a lineHint obtained from localSearchCode first, Node.js 20.12+ is a prerequisite, and GitHub authentication is optional but needed for private repositories and higher API rate limits.
GitHub stars944Stars / 30 days+28npm / typical week2.3KPyPI / typical weekno attributed packageTools exposed13Last commit33 days agoCommits / 12 weeks24Maintenance gradeATool descriptionsAScore 67.9: show every number behind it
- Adoption85 / 100 · weight 40%
- GitHub stars74
- npm downloads72
- Used through Glamanot measurednot used through Glama in the last 30 days
- Maintenance97 / 100 · weight 24%
- Last commit touching this server100
- Repository maintenance grade100
- Commit cadence85
- Momentum55 / 100 · weight 14%
- Stars gained, relative to size66
- Stars gained, absolute59
- npm download trend33
- Tool quality100 / 100 · weight 13%
- Tool description quality93
- Built and inspected by Glama100
- Trust100 / 100 · weight 9%
- License100
- Published by the vendor it integratesnot measurednot published by the vendor it integrates
- Weighted mean of the five
- 87.1
- × relevance: the keyword is declared here
- 0.78
- × continuity: actively changing
- 1.00
- × evidence: widely adopted
- 1.00
- Composite score
- 67.9
Best for: Sprint and milestone tracking on GitHub Projects V2: it exposes 84 tools covering roadmaps, milestones, sprint metrics, draft issues, and pull request reviews.
The server implements the Model Context Protocol over GitHub Projects V2, exposing 84 tools that create and update projects, roadmaps, milestones, sprints, issues, draft issues, and pull requests, plus progress metrics for milestones and sprints. Choosing it does assume a GitHub Projects V2 board to run against, since its README states that all state lives in GitHub issues, project fields, and comments, with no external database or other infrastructure required.
GitHub stars101Stars / 30 days+9npm / typical week56PyPI / typical weekno attributed packageTools exposed84Last commit5 days agoCommits / 12 weeks81Maintenance gradeCTool descriptionsCScore 67.5: show every number behind it
- Adoption56 / 100 · weight 40%
- GitHub stars50
- npm downloads37
- Used through Glamanot measurednot used through Glama in the last 30 days
- Maintenance89 / 100 · weight 24%
- Last commit touching this server100
- Repository maintenance grade55
- Commit cadence100
- Momentum59 / 100 · weight 14%
- Stars gained, relative to size76
- Stars gained, absolute40
- npm download trend52
- Tool quality51 / 100 · weight 13%
- Tool description quality43
- Built and inspected by Glama100
- Trust100 / 100 · weight 9%
- License100
- Published by the vendor it integratesnot measurednot published by the vendor it integrates
- Weighted mean of the five
- 67.5
- × relevance: the keyword is dedicated here
- 1.00
- × continuity: actively changing
- 1.00
- × evidence: widely adopted
- 1.00
- Composite score
- 67.5
Best for: Before building a product idea: it exposes idea_check to check whether that idea already exists.
idea-reality-mcp exposes one MCP tool, idea_check, which checks a plain-English product idea against external sources and returns a reality signal with competitor evidence, trend direction, and pivot suggestions. It is scoped to that pre-build check, so it does not cover general GitHub repository, issue, or pull request operations.
GitHub stars821Stars / 30 days+19npm / typical weekShips no npm packagePyPI / typical week70idea-reality-mcpTools exposed1Last commit9 days agoCommits / 12 weeks37Maintenance gradeCTool descriptionsAScore 61.9: show every number behind it
- Adoption76 / 100 · weight 40%
- GitHub stars73
- PyPI downloads20PyPI downloads show no weekday rhythm; halved
- Used through Glamanot measurednot used through Glama in the last 30 days
- Maintenance89 / 100 · weight 24%
- Last commit touching this server100
- Repository maintenance grade55
- Commit cadence100
- Momentum47 / 100 · weight 14%
- Stars gained, relative to size57
- Stars gained, absolute52
- PyPI download trend24
- Tool quality93 / 100 · weight 13%
- Tool description quality85
- Built and inspected by Glama100
- Trust100 / 100 · weight 9%
- License100
- Published by the vendor it integratesnot measurednot published by the vendor it integrates
- Weighted mean of the five
- 79.4
- × relevance: the keyword is declared here
- 0.78
- × continuity: actively changing
- 1.00
- × evidence: widely adopted
- 1.00
- Composite score
- 61.9
Best for: Debugging a library or cloud error and needing StackOverflow or GitHub Issue answers, not snippets: it returns full conversations and structured content in one call.
Its README documents a web_search interface returning titles, links, snippets, and best-effort Markdown page content, and a get_content interface for retrieving Markdown from a URL, with structured content from StackOverflow, GitHub Issues, arXiv, and Wikipedia. No npm package is published and no PyPI package is attributed to it.
GitHub stars395Stars / 30 days+18npm / typical weekShips no npm packagePyPI / typical weekno attributed packageTools exposednever inspectedLast committodayCommits / 12 weeks304Maintenance gradeATool descriptionsNot gradedScore 60.0: show every number behind it
- Adoption65 / 100 · weight 40%
- GitHub stars65
- npm downloadsnot measuredno npm package
- Used through Glamanot measurednot used through Glama in the last 30 days
- Maintenance100 / 100 · weight 24%
- Last commit touching this server100
- Repository maintenance grade100
- Commit cadence100
- Momentum65 / 100 · weight 14%
- Stars gained, relative to size75
- Stars gained, absolute51
- npm download trendnot measuredno download history for the selected registry
- Tool quality≈68 / 100 · weight 13%
- Tool description quality≈68tool descriptions not yet scored
- Built and inspected by Glamanot measurednever built and inspected by Glama
- Trust100 / 100 · weight 9%
- License100
- Published by the vendor it integratesnot measurednot published by the vendor it integrates
- Weighted mean of the five
- 76.9
- × relevance: the keyword is declared here
- 0.78
- × continuity: actively changing
- 1.00
- × evidence: widely adopted
- 1.00
- Composite score
- 60.0
Best for: Preventing duplicate code before committing: it exposes check_duplication, get_file_clones, get_statistics, and check_current_directory against the scanned project.
jscpd's built-in MCP server runs over stdio and exposes four tools: check_duplication for snippets, get_file_clones and get_statistics for the last scan, and check_current_directory to re-scan the paths it was started with. The scope is the scanned project: results come from the last scan or the paths the server was started with, so changing those paths requires starting jscpd --mcp with the new project.
GitHub stars6,273Stars / 30 days+181npm / typical weekShips no npm packagePyPI / typical weekno attributed packageTools exposed4Last committodayCommits / 12 weeks449Maintenance gradeATool descriptionsAScore 56.9: show every number behind it
- Adoption95 / 100 · weight 40%
- GitHub stars95
- npm downloadsnot measuredno npm package
- Used through Glamanot measurednot used through Glama in the last 30 days
- Maintenance100 / 100 · weight 24%
- Last commit touching this server100
- Repository maintenance grade100
- Commit cadence100
- Momentum78 / 100 · weight 14%
- Stars gained, relative to size69
- Stars gained, absolute91
- npm download trendnot measuredno download history for the selected registry
- Tool quality100 / 100 · weight 13%
- Tool description quality93
- Built and inspected by Glama100
- Trust100 / 100 · weight 9%
- License100
- Published by the vendor it integrates100
- Weighted mean of the five
- 94.8
- × relevance: the keyword is tagged here
- 0.60
- × continuity: actively changing
- 1.00
- × evidence: widely adopted
- 1.00
- Composite score
- 56.9
Best for: Finding a previously starred repository by description rather than keyword: it exposes a natural language search tool backed by Cloudflare AutoRAG over repository READMEs.
GitHub Stars MCP Server fetches a GitHub account's starred repositories and their README files into Cloudflare R2, builds an AutoRAG index over that content, and serves it through a streamable HTTP endpoint with a search_github_stars tool that accepts a natural language query. Before choosing it, note that it is self-hosted rather than a hosted service: it requires a Cloudflare account with an R2 bucket and AutoRAG instance configured, a GitHub personal access token with repo scope, and an MCP_API_KEY, since requests are authenticated with a bearer token.
GitHub stars116Stars / 30 days+4npm / typical weekdownloads not countedPyPI / typical weekno attributed packageTools exposednever inspectedLast commityesterdayCommits / 12 weeks15Maintenance gradeBTool descriptionsNot gradedScore 56.6: show every number behind it
- Adoption52 / 100 · weight 40%
- GitHub stars52
- npm downloadsnot measurednpm names no repository for mcp-github-stars, so its downloads cannot be attributed
- Used through Glamanot measurednot used through Glama in the last 30 days
- Maintenance92 / 100 · weight 24%
- Last commit touching this server100
- Repository maintenance grade80
- Commit cadence85
- Momentum43 / 100 · weight 14%
- Stars gained, relative to size52
- Stars gained, absolute29
- npm download trendnot measuredno download history for the selected registry
- Tool quality≈68 / 100 · weight 13%
- Tool description quality≈68tool descriptions not yet scored
- Built and inspected by Glamanot measurednever built and inspected by Glama
- Trust100 / 100 · weight 9%
- License100
- Published by the vendor it integratesnot measurednot published by the vendor it integrates
- Weighted mean of the five
- 66.6
- × relevance: the keyword is dedicated here
- 1.00
- × continuity: actively changing
- 1.00
- × evidence: modest but real audience
- 0.85
- Composite score
- 56.6
Best for: AI assistants needing current documentation and code for a specific GitHub repository: it exposes remote MCP endpoints such as gitmcp.io/{owner}/{repo} and gitmcp.io/docs.
GitMCP exposes 32 tools for Git operations, Gitea and GitHub repository management, authentication, configuration, releases, versioning, backups, and health checks, while its README documents remote MCP endpoints that turn GitHub repositories or GitHub Pages sites into documentation sources. Before choosing it, note that the documented hosted setup requires adding a GitMCP URL such as gitmcp.io/{owner}/{repo} or gitmcp.io/docs as an MCP server in an AI assistant or IDE.
GitHub stars8,417Stars / 30 days+76npm / typical weekdownloads not countedPyPI / typical weekno attributed packageTools exposed32Last commit142 days agoCommits / 12 weeks0Maintenance gradeFTool descriptionsCScore 56.3: show every number behind it
- Adoption98 / 100 · weight 40%
- GitHub stars98
- npm downloadsnot measurednpm names no repository for git-mcp, so its downloads cannot be attributed
- Used through Glamanot measurednot used through Glama in the last 30 days
- Maintenance40 / 100 · weight 24%
- Last commit touching this server68
- Repository maintenance grade5
- Commit cadence5
- Momentum54 / 100 · weight 14%
- Stars gained, relative to size38
- Stars gained, absolute76
- npm download trendnot measuredno download history for the selected registry
- Tool quality53 / 100 · weight 13%
- Tool description quality45
- Built and inspected by Glama100
- Trust100 / 100 · weight 9%
- License100
- Published by the vendor it integratesnot measurednot published by the vendor it integrates
- Weighted mean of the five
- 72.2
- × relevance: the keyword is declared here
- 0.78
- × continuity: actively changing
- 1.00
- × evidence: widely adopted
- 1.00
- Composite score
- 56.3
Best for: Incident response and dependency triage on a known CVE list: 41 tools pull NVD, EPSS, KEV and OSV data and rank vulnerabilities by exploitation risk.
cve-mcp exposes 41 tools that query NVD, EPSS, CISA KEV, GitHub Advisory, OSV, Shodan, VulnCheck, Vulners, Nuclei, Metasploit, CIRCL and AttackerKB for CVE lookup, package and CPE matching, exploit and weaponization checks, and CVE prioritization, comparison and enrichment. Before choosing it, note that it is distributed as an npm package whose README badges Bun as the runtime, and that some of the aggregated sources accept optional API keys, with a source-status tool reporting which keys are configured.
GitHub stars28Stars / 30 days+11npm / typical week385PyPI / typical weekno attributed packageTools exposed41Last commit83 days agoCommits / 12 weeks3Maintenance gradeBTool descriptionsAScore 54.4: show every number behind it
- Adoption61 / 100 · weight 40%
- GitHub stars37
- npm downloads55
- Used through Glamanot measurednot used through Glama in the last 30 days
- Maintenance76 / 100 · weight 24%
- Last commit touching this server88dated from the last commit on the default branch, re-read from GitHub at publication; github.com shows a push 11 days ago, which counts every ref; the stored date would have published 11 days ago
- Repository maintenance grade80
- Commit cadence40
- Momentum60 / 100 · weight 14%
- Stars gained, relative to size100
- Stars gained, absolute43
- npm download trend8
- Tool quality76 / 100 · weight 13%
- Tool description quality68
- Built and inspected by Glama100
- Trust100 / 100 · weight 9%
- License100
- Published by the vendor it integratesnot measurednot published by the vendor it integrates
- Weighted mean of the five
- 69.7
- × relevance: the keyword is declared here
- 0.78
- × continuity: actively changing
- 1.00
- × evidence: widely adopted
- 1.00
- Composite score
- 54.4
Best for: Preparing AI skills or RAG knowledge from mixed sources: it scrapes GitHub repos, docs sites, PDFs, and videos and exports to vector databases.
Skill Seekers exposes 40 MCP tools that scrape documentation sites, GitHub repositories, PDFs, videos, notebooks, wikis, and local codebases into packaged Claude, Gemini, or OpenAI skills, or into vector-database exports. It assumes Python 3.10 or newer and installation from PyPI as skill-seekers, with the MCP server added through the skill-seekers[mcp] extra.
GitHub stars15,020Stars / 30 days+213npm / typical weekShips no npm packagePyPI / typical week3.7Kskill-seekersTools exposed40Last commit7 days agoCommits / 12 weeks108Maintenance gradeATool descriptionsBScore 52.9: show every number behind it
- Adoption100 / 100 · weight 40%
- GitHub stars100
- PyPI downloads38PyPI downloads show no weekday rhythm; halved
- Used through Glamanot measurednot used through Glama in the last 30 days
- Maintenance100 / 100 · weight 24%
- Last commit touching this server100
- Repository maintenance grade100
- Commit cadence100
- Momentum52 / 100 · weight 14%
- Stars gained, relative to size49
- Stars gained, absolute94
- PyPI download trend9
- Tool quality61 / 100 · weight 13%
- Tool description quality53
- Built and inspected by Glama100
- Trust100 / 100 · weight 9%
- License100
- Published by the vendor it integratesnot measurednot published by the vendor it integrates
- Weighted mean of the five
- 88.2
- × relevance: the keyword is tagged here
- 0.60
- × continuity: actively changing
- 1.00
- × evidence: widely adopted
- 1.00
- Composite score
- 52.9
Best for: Static analysis before merge in an MCP-compatible coding agent: it exposes twelve tools for dead code, security, secrets, quality, and diff validation.
mcp-skylos is an MCP server that exposes twelve static-analysis tools, including analyze, security_scan, secrets_scan, quality_check, and validate_code_change, and returns findings with file paths, line numbers, and severity. Its MCP description names Python, TypeScript, and Go as scan targets, while the README documents a broader CLI language list.
GitHub stars836Stars / 30 days+381npm / typical weekShips no npm packagePyPI / typical week16.3KskylosTools exposed12Last committodayCommits / 12 weeks173Maintenance gradeATool descriptionsDScore 52.8: show every number behind it
- Adoption100 / 100 · weight 40%
- GitHub stars73
- PyPI downloads90
- Used through Glamanot measurednot used through Glama in the last 30 days
- Maintenance100 / 100 · weight 24%
- Last commit touching this server100
- Repository maintenance grade100
- Commit cadence100
- Momentum81 / 100 · weight 14%
- Stars gained, relative to size100
- Stars gained, absolute100
- PyPI download trend23
- Tool quality28 / 100 · weight 13%
- Tool description quality20
- Built and inspected by Glama100
- Trust100 / 100 · weight 9%
- License100
- Published by the vendor it integratesnot measurednot published by the vendor it integrates
- Weighted mean of the five
- 88.0
- × relevance: the keyword is tagged here
- 0.60
- × continuity: actively changing
- 1.00
- × evidence: widely adopted
- 1.00
- Composite score
- 52.8
Best for: Securing an agent that calls MCP servers with secrets: it proxies MCP traffic and scans bidirectionally for credential leaks, prompt injection, and tool description poisoning.
Pipelock is a security proxy that wraps any MCP server and inspects mediated HTTP, WebSocket, MCP, and A2A traffic, scanning bidirectionally for credential leaks, prompt injection, and tool description poisoning. Before choosing it, know that no npm package is published and no PyPI package is attributed, and CONNECT tunnel content scanning requires TLS interception, so setup is not a package-manager one-liner.
GitHub stars905Stars / 30 days+101npm / typical weekShips no npm packagePyPI / typical weekno attributed packageTools exposednever inspectedLast committodayCommits / 12 weeks755Maintenance gradeATool descriptionsNot gradedScore 50.6: show every number behind it
- Adoption74 / 100 · weight 40%
- GitHub stars74
- npm downloadsnot measuredno npm package
- Used through Glamanot measurednot used through Glama in the last 30 days
- Maintenance100 / 100 · weight 24%
- Last commit touching this server100
- Repository maintenance grade100
- Commit cadence100
- Momentum92 / 100 · weight 14%
- Stars gained, relative to size100
- Stars gained, absolute81
- npm download trendnot measuredno download history for the selected registry
- Tool quality≈68 / 100 · weight 13%
- Tool description quality≈68tool descriptions not yet scored
- Built and inspected by Glamanot measurednever built and inspected by Glama
- Trust100 / 100 · weight 9%
- License100
- Published by the vendor it integratesnot measurednot published by the vendor it integrates
- Weighted mean of the five
- 84.3
- × relevance: the keyword is tagged here
- 0.60
- × continuity: actively changing
- 1.00
- × evidence: widely adopted
- 1.00
- Composite score
- 50.6
Best for: Autonomous spec-driven builds inside a repository, where the MCP client needs project state, task-queue, memory, code-search, and verification tools over stdio.
Loki Mode is an autonomous spec-to-product coding-agent CLI whose MCP server is described as exposing stdio tools for project state, task queues, memory, code search, quality and verification reports, repository hotspots and co-changes, and structured findings. The thing to know before choosing it is that the Claude Code plugin assumes the loki-mode CLI is already installed, because the plugin calls the CLI rather than bundling it.
GitHub stars1,072Stars / 30 days+22npm / typical week2.1KPyPI / typical weekno attributed packageTools exposednever inspectedLast committodayCommits / 12 weeks929Maintenance gradeATool descriptionsNot gradedScore 49.2: show every number behind it
- Adoption86 / 100 · weight 40%
- GitHub stars76
- npm downloads71
- Used through Glamanot measurednot used through Glama in the last 30 days
- Maintenance100 / 100 · weight 24%
- Last commit touching this server100
- Repository maintenance grade100
- Commit cadence100
- Momentum41 / 100 · weight 14%
- Stars gained, relative to size55
- Stars gained, absolute55
- npm download trend0
- Tool quality≈68 / 100 · weight 13%
- Tool description quality≈68tool descriptions not yet scored
- Built and inspected by Glamanot measurednever built and inspected by Glama
- Trust100 / 100 · weight 9%
- License100
- Published by the vendor it integratesnot measurednot published by the vendor it integrates
- Weighted mean of the five
- 82.0
- × relevance: the keyword is tagged here
- 0.60
- × continuity: actively changing
- 1.00
- × evidence: widely adopted
- 1.00
- Composite score
- 49.2
Best for: Teams automating GitHub Actions, pull requests, code search, and repository management from an MCP client: it documents compact, JSON, and Markdown response formats.
Its README documents GitHub workflow automation for Actions monitoring, pull request management, code search, file operations, and repository management, with compact, JSON, and Markdown response formats and a code-first mode enabled by default. Before choosing it, note that its tool list has not been inspected, so the advertised tool count cannot be confirmed; installation assumes Python 3.10+ and the PyPI package github-mcp-server, with no npm package published.
GitHub stars5Stars / 30 days+1npm / typical weekShips no npm packagePyPI / typical week102github-mcp-serverTools exposednever inspectedLast commit61 days agoCommits / 12 weeks1Maintenance gradeBTool descriptionsNot gradedScore 49.2: show every number behind it
- Adoption46 / 100 · weight 40%
- GitHub stars19
- PyPI downloads43
- Used through Glamanot measurednot used through Glama in the last 30 days
- Maintenance76 / 100 · weight 24%
- Last commit touching this server88
- Repository maintenance grade80
- Commit cadence40
- Momentum25 / 100 · weight 14%
- Stars gained, relative to size39
- Stars gained, absolute16
- PyPI download trend11
- Tool quality≈68 / 100 · weight 13%
- Tool description quality≈68tool descriptions not yet scored
- Built and inspected by Glamanot measurednever built and inspected by Glama
- Trust100 / 100 · weight 9%
- License100
- Published by the vendor it integratesnot measurednot published by the vendor it integrates
- Weighted mean of the five
- 57.9
- × relevance: the keyword is dedicated here
- 1.00
- × continuity: actively changing
- 1.00
- × evidence: modest but real audience
- 0.85
- Composite score
- 49.2
Best for: Running authorized coding, bug-fixing, tests or refactors in Claude Code or Cursor while capping session spend: it enforces budgets, preflight validation and verifier safety gates.
MartinLoop exposes 24 MCP tools for governed coding runs, including planning with martin_plan, preflight validation, execution via martin_run, budget and stop-pressure checks, run dossiers, verification results, and GitHub PR creation with martin_create_pr. Before choosing it, note that completion requires fresh verifier evidence bound to the active run and workspace, so a VERIFIED result does not claim the code is bug-free or automatically safe to merge.
GitHub stars192Stars / 30 days+181npm / typical week217PyPI / typical weekno attributed packageTools exposed24Last committodayCommits / 12 weeks441Maintenance gradeATool descriptionsAScore 47.8: show every number behind it
- Adoption61 / 100 · weight 40%
- GitHub stars57
- npm downloads25downloads show none of the weekday rhythm human traffic has; halved
- Used through Glamanot measurednot used through Glama in the last 30 days
- Maintenance100 / 100 · weight 24%
- Last commit touching this server100
- Repository maintenance grade100
- Commit cadence100
- Momentum90 / 100 · weight 14%
- Stars gained, relative to size100
- Stars gained, absolute91
- npm download trend69
- Tool quality76 / 100 · weight 13%
- Tool description quality68
- Built and inspected by Glama100
- Trust100 / 100 · weight 9%
- License100
- Published by the vendor it integratesnot measurednot published by the vendor it integrates
- Weighted mean of the five
- 79.7
- × relevance: the keyword is tagged here
- 0.60
- × continuity: actively changing
- 1.00
- × evidence: widely adopted
- 1.00
- Composite score
- 47.8
Best for: Auditing a GitHub org's security posture from an AI agent: 39 tools across org settings, repository config, workflows, secrets, supply chain and access control.
The server exposes 39 tools that call GitHub APIs to inspect organization settings such as 2FA enforcement and SSO, repository configuration including branch protection, secret scanning, code scanning and Dependabot, Actions workflow risks such as script injection and unpinned actions, secret and supply chain coverage, and team, collaborator, GitHub App and PAT access, with aggregation and markdown report tools over the findings collected in a session. Before installing, note that it runs on Bun and expects a GITHUB_TOKEN carrying repo, admin:org, admin:org_hook and admin:repo_hook scopes, with Enterprise-only features handled by graceful degradation rather than full coverage through the public API.
GitHub stars13Stars / 30 days+1npm / typical week207PyPI / typical weekno attributed packageTools exposed39Last commit197 days agoCommits / 12 weeks0Maintenance gradeDTool descriptionsAScore 46.2: show every number behind it
- Adoption54 / 100 · weight 40%
- GitHub stars29
- npm downloads49
- Used through Glamanot measurednot used through Glama in the last 30 days
- Maintenance46 / 100 · weight 24%
- Last commit touching this server68
- Repository maintenance grade30
- Commit cadence5
- Momentum22 / 100 · weight 14%
- Stars gained, relative to size38
- Stars gained, absolute16
- npm download trend0
- Tool quality76 / 100 · weight 13%
- Tool description quality68
- Built and inspected by Glama100
- Trust100 / 100 · weight 9%
- License100
- Published by the vendor it integratesnot measurednot published by the vendor it integrates
- Weighted mean of the five
- 54.4
- × relevance: the keyword is dedicated here
- 1.00
- × continuity: actively changing
- 1.00
- × evidence: modest but real audience
- 0.85
- Composite score
- 46.2
Best for: Securing GitHub-connected agents that run with permissions skipped: it hooks every tool call, blocking credential-file reads and holding destructive git or shell actions for review.
Node9-Proxy is a hook-based gate for MCP tool calls, with its README documenting a credential jail, approval holds for destructive git, SQL and shell actions, MCP tool pinning, a network egress allowlist, a loop breaker, and audit logging across agents. Choosing it requires Node.js 22+ and a
node9 initrun in each project to install the hooks; the README presents it as governing other agents and MCP servers rather than exposing its own GitHub tool set.GitHub stars216Stars / 30 days+8npm / typical week1.2KPyPI / typical weekno attributed packageTools exposednever inspectedLast committodayCommits / 12 weeks707Maintenance gradeATool descriptionsNot gradedScore 45.7: show every number behind it
- Adoption63 / 100 · weight 40%
- GitHub stars58
- npm downloads33downloads show none of the weekday rhythm human traffic has; halved
- Used through Glamanot measurednot used through Glama in the last 30 days
- Maintenance100 / 100 · weight 24%
- Last commit touching this server100
- Repository maintenance grade100
- Commit cadence100
- Momentum64 / 100 · weight 14%
- Stars gained, relative to size62
- Stars gained, absolute39
- npm download trend100
- Tool quality≈68 / 100 · weight 13%
- Tool description quality≈68tool descriptions not yet scored
- Built and inspected by Glamanot measurednever built and inspected by Glama
- Trust100 / 100 · weight 9%
- License100
- Published by the vendor it integratesnot measurednot published by the vendor it integrates
- Weighted mean of the five
- 76.2
- × relevance: the keyword is tagged here
- 0.60
- × continuity: actively changing
- 1.00
- × evidence: widely adopted
- 1.00
- Composite score
- 45.7
- 19
Best for: Managing AI personas and other reusable elements in a local portfolio: it exposes five tools spanning create, read, update, delete and execute.
DollhouseMCP exposes five tools (create, read, update, delete, execute) that manage personas, skills, templates, agents, memories and ensembles held in a local portfolio folder, with community sharing and GitHub sync. Its README states that permission hook support is full only on Claude Code and that Claude Desktop has no native permission hook path in this release, so the confirmation and agentic loop features depend on which client it is installed into.
GitHub stars44Stars / 30 days+4npm / typical week301PyPI / typical weekno attributed packageTools exposed5Last commit6 days agoCommits / 12 weeks128Maintenance gradeBTool descriptionsAScore 44.5: show every number behind it
- Adoption45 / 100 · weight 40%
- GitHub stars41
- npm downloads26downloads show none of the weekday rhythm human traffic has; halved
- Used through Glama14
- Maintenance95 / 100 · weight 24%
- Last commit touching this server100
- Repository maintenance grade80
- Commit cadence100
- Momentum37 / 100 · weight 14%
- Stars gained, relative to size60
- Stars gained, absolute29
- npm download trend4
- Tool quality93 / 100 · weight 13%
- Tool description quality85
- Built and inspected by Glama100
- Trust100 / 100 · weight 9%
- License100
- Published by the vendor it integratesnot measurednot published by the vendor it integrates
- Weighted mean of the five
- 67.1
- × relevance: the keyword is declared here
- 0.78
- × continuity: actively changing
- 1.00
- × evidence: modest but real audience
- 0.85
- Composite score
- 44.5
Best for: Summarizing a GitHub organization's issues, discussions, and pull requests beyond the standard API item limit: it stores data locally and returns token-efficient Markdown.
GitHub Brain MCP Server summarizes discussions, issues, and pull requests from a local database populated through its interactive TUI, and its README documents a stdio MCP server started with
github-brain mcpfor Claude and VS Code. Before adoption, note that the MCP server requires a GitHub organization via-oorORGANIZATION, reads only from the local database after a Pull, and complements rather than replaces the official GitHub MCP server.GitHub stars78Stars / 30 days0npm / typical week14PyPI / typical weekno attributed packageTools exposednever inspectedLast commit235 days agoCommits / 12 weeks0Maintenance gradeCTool descriptionsNot gradedScore 43.8: show every number behind it
- Adoption49 / 100 · weight 40%
- GitHub stars47
- npm downloads13downloads show none of the weekday rhythm human traffic has; halved
- Used through Glamanot measurednot used through Glama in the last 30 days
- Maintenance52 / 100 · weight 24%
- Last commit touching this server68
- Repository maintenance grade55
- Commit cadence5
- Momentum11 / 100 · weight 14%
- Stars gained, relative to size0
- Stars gained, absolute0
- npm download trend44
- Tool quality≈68 / 100 · weight 13%
- Tool description quality≈68tool descriptions not yet scored
- Built and inspected by Glamanot measurednever built and inspected by Glama
- Trust100 / 100 · weight 9%
- License100
- Published by the vendor it integratesnot measurednot published by the vendor it integrates
- Weighted mean of the five
- 51.5
- × relevance: the keyword is dedicated here
- 1.00
- × continuity: actively changing
- 1.00
- × evidence: modest but real audience
- 0.85
- Composite score
- 43.8
Questions people ask
What does GitHub MCP Server require before it will run?
GitHub MCP Server (github/github-mcp-server) installs as a remote HTTP MCP server at api.githubcopilot.com/mcp/ using OAuth or a PAT. The evidence above lists no npm package published and no PyPI package attributed for it, so the setup described is the remote endpoint rather than a local package install. Its default branch had a commit 11 days ago and 184 commits in the last 12 weeks.
What should I be careful about when using github-security-mcp?
github-security-mcp (badchars/github-security-mcp) is labeled Dormant, and its default branch had a commit 197 days ago with 0 commits in the last 12 weeks. It exposes 39 tools across org settings, repository config, workflows, secrets, supply chain, and access control, and its tool descriptions are graded A. If you need active maintenance, check that record before pointing an agent at it for security audits.
Which server should I use for GitHub Projects V2 tracking?
Use mcp-github-project-manager (kunwarVivek/mcp-github-project-manager). It exposes 84 tools covering roadmaps, milestones, sprint metrics, draft issues, and pull request reviews, and its default branch had a commit 5 days ago with 81 commits in the last 12 weeks. Its tool descriptions are graded C, so expect weaker tool descriptions than servers graded A.
Can GitMCP still work for current repository documentation?
GitMCP (idosal/git-mcp) exposes remote MCP endpoints such as gitmcp.io/{owner}/{repo} and gitmcp.io/docs, and it has 8,417 GitHub stars. It is labeled Abandoned but popular, its default branch had a commit 142 days ago, and it has 0 commits in the last 12 weeks. It also exposes 32 tools with tool descriptions graded C.
How do I secure an agent that calls GitHub MCP servers with secrets?
Use pipelock (luckyPipewrench/pipelock), which proxies MCP traffic and scans bidirectionally for credential leaks, prompt injection, and tool description poisoning. It had a commit 0 days ago and 755 commits in the last 12 weeks. Node9-Proxy (node9-ai/node9-proxy) is another option: it hooks every tool call, blocking credential-file reads and holding destructive git or shell actions for review, and @node9/proxy had 1,180 npm downloads in a typical week.