Skip to main content
Glama
jmass-ggg

GitHub Security Analyzer — MCP

by jmass-ggg

GitHub Security Analyzer — MCP

AIを活用したGitHubセキュリティスキャナーです。GitHubアカウントでログインし、リポジトリ名を指定すると、AIがすべてのファイルをスキャンしてAPIキー、パスワード、トークンなどの露出したシークレットを検出し、修正すべき点を含む完全なレポートを提供します。


仕組み

1. Login with GitHub (OAuth)
        ↓
   .github_token saved locally
        ↓
2. Run the agent
        ↓
   You type a repo name
        ↓
3. AI calls deep_security_scan tool
        ↓
   Fetches every file from the repo via GitHub API
        ↓
   Scans each file with 16 secret patterns (regex)
        ↓
4. AI reads the results and writes a report
        ↓
   Tells you what was found, which file, which line, and how to fix it

Related MCP server: github-security-mcp

プロジェクト構成

├── login.py          # GitHub OAuth login — saves token to .github_token
├── github_client.py  # Wrapper around GitHub API calls
├── server.py         # MCP tools (list repos, scan files, read code, etc.)
├── agent.py          # AI agent loop — uses OpenRouter to run the scanner
├── requirements.txt  # Python dependencies
└── .env              # Your credentials (never commit this)

セットアップ

1. .env ファイルを作成:

GITHUB_CLIENT_ID=your_github_app_client_id
GITHUB_CLIENT_SECRET=your_github_app_client_secret
FLASK_SECRET_KEY=any_random_string
OPENROUTER_API_KEY=your_openrouter_key

2. 依存関係をインストール:

pip install -r requirements.txt

3. GitHubでログイン:

python login.py

http://127.0.0.1:5000 を開く → 「Login with Github」をクリック → 認可 → 完了。 これによりトークンが .github_token に保存されます。この操作は一度だけ行えば十分です。


実行方法

オプションA — AIエージェント(ターミナル)

python agent.py

プロンプトが表示されたらリポジトリ名を入力します。AIがスキャンし、完全なセキュリティレポートを出力します。

オプションB — MCPサーバー(Claude Desktopまたは任意のMCPクライアント用)

mcp dev server.py

スキャン対象

シークレットの種類

パターン例

AWSアクセスキー

AKIA...

GitHubトークン

ghp_...

Google APIキー

AIza...

Stripeキー

sk_live_...

データベースURL

postgres://user:pass@host

一般的なパスワード

password = "..."

秘密鍵

-----BEGIN RSA PRIVATE KEY-----

ベアラートークン

Authorization: Bearer ...

Slack / Twilio / SendGridトークン

各種パターン


利用可能なMCPツール

ツール

機能

list_repositories

すべてのGitHubリポジトリを一覧表示

repository_details

特定のリポジトリの詳細を取得

read_file

ファイルからソースコードを読み取る

issues

オープン中のGitHub issueを一覧表示

code_change_summary

最近のコミットメッセージを取得

security_scan

ファイル名を機密性の高い単語で簡易スキャン

deep_security_scan

全ファイルの内容をシークレット検出で完全スキャン


重要

  • .github_token.env をコミットしないでください — どちらも .gitignore に含まれています

  • 誤ってトークンをプッシュした場合は、https://github.com/settings/tokens ですぐに失効させてください

F
license - not found
Not graded
quality - not tested
C
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    A
    quality
    Not graded
    maintenance
    Enterprise-grade MCP (Model Context Protocol) server for detecting secrets and sensitive information in GitHub repositories. Scans for 35+ types of secrets including API keys, passwords, tokens, and credentials with production-ready reliability features.
    5
    0
  • A
    license
    A
    quality
    D
    maintenance
    An MCP server that enables AI agents to perform comprehensive GitHub security audits across org settings, repositories, Actions workflows, secrets, supply chain, and access control using 39 tools and 45 checks.
    39
    521
    12
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    An MCP server for AI security analysis, enabling vulnerability scanning, sensitive information leak detection, and GitHub code leak monitoring via 48 tools.
    MIT

View all related MCP servers

Related MCP Connectors

  • Scans MCP servers for tool poisoning, prompt injection and supply chain risks.

  • Scan any public GitHub MCP-server repo for security issues. 37 MCP-specific L1 rules, 8 languages.

  • Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/jmass-ggg/Github-Security-analyze-MCP'

If you have feedback or need assistance with the MCP directory API, please join our Discord server