GitHub Security Analyzer — MCP
GitHub Security Analyzer — MCP
AIを活用したGitHubセキュリティスキャナーです。GitHubアカウントでログインし、リポジトリ名を指定すると、AIがすべてのファイルをスキャンしてAPIキー、パスワード、トークンなどの露出したシークレットを検出し、修正すべき点を含む完全なレポートを提供します。
仕組み
1. Login with GitHub (OAuth)
↓
.github_token saved locally
↓
2. Run the agent
↓
You type a repo name
↓
3. AI calls deep_security_scan tool
↓
Fetches every file from the repo via GitHub API
↓
Scans each file with 16 secret patterns (regex)
↓
4. AI reads the results and writes a report
↓
Tells you what was found, which file, which line, and how to fix itRelated MCP server: github-security-mcp
プロジェクト構成
├── login.py # GitHub OAuth login — saves token to .github_token
├── github_client.py # Wrapper around GitHub API calls
├── server.py # MCP tools (list repos, scan files, read code, etc.)
├── agent.py # AI agent loop — uses OpenRouter to run the scanner
├── requirements.txt # Python dependencies
└── .env # Your credentials (never commit this)セットアップ
1. .env ファイルを作成:
GITHUB_CLIENT_ID=your_github_app_client_id
GITHUB_CLIENT_SECRET=your_github_app_client_secret
FLASK_SECRET_KEY=any_random_string
OPENROUTER_API_KEY=your_openrouter_key2. 依存関係をインストール:
pip install -r requirements.txt3. GitHubでログイン:
python login.pyhttp://127.0.0.1:5000 を開く → 「Login with Github」をクリック → 認可 → 完了。
これによりトークンが .github_token に保存されます。この操作は一度だけ行えば十分です。
実行方法
オプションA — AIエージェント(ターミナル)
python agent.pyプロンプトが表示されたらリポジトリ名を入力します。AIがスキャンし、完全なセキュリティレポートを出力します。
オプションB — MCPサーバー(Claude Desktopまたは任意のMCPクライアント用)
mcp dev server.pyスキャン対象
シークレットの種類 | パターン例 |
AWSアクセスキー |
|
GitHubトークン |
|
Google APIキー |
|
Stripeキー |
|
データベースURL |
|
一般的なパスワード |
|
秘密鍵 |
|
ベアラートークン |
|
Slack / Twilio / SendGridトークン | 各種パターン |
利用可能なMCPツール
ツール | 機能 |
| すべてのGitHubリポジトリを一覧表示 |
| 特定のリポジトリの詳細を取得 |
| ファイルからソースコードを読み取る |
| オープン中のGitHub issueを一覧表示 |
| 最近のコミットメッセージを取得 |
| ファイル名を機密性の高い単語で簡易スキャン |
| 全ファイルの内容をシークレット検出で完全スキャン |
重要
.github_tokenや.envをコミットしないでください — どちらも.gitignoreに含まれています誤ってトークンをプッシュした場合は、
https://github.com/settings/tokensですぐに失効させてください
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseAqualityNot gradedmaintenanceEnterprise-grade MCP (Model Context Protocol) server for detecting secrets and sensitive information in GitHub repositories. Scans for 35+ types of secrets including API keys, passwords, tokens, and credentials with production-ready reliability features.50
- AlicenseAqualityDmaintenanceAn MCP server that enables AI agents to perform comprehensive GitHub security audits across org settings, repositories, Actions workflows, secrets, supply chain, and access control using 39 tools and 45 checks.3952112MIT
- AlicenseNot gradedqualityCmaintenanceMCP server for ai-scanner that enables AI agents to scan codebases for LLM usage, AI frameworks, and exposed secrets.641MIT
- AlicenseNot gradedqualityCmaintenanceAn MCP server for AI security analysis, enabling vulnerability scanning, sensitive information leak detection, and GitHub code leak monitoring via 48 tools.MIT
Related MCP Connectors
Scans MCP servers for tool poisoning, prompt injection and supply chain risks.
Scan any public GitHub MCP-server repo for security issues. 37 MCP-specific L1 rules, 8 languages.
Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/jmass-ggg/Github-Security-analyze-MCP'
If you have feedback or need assistance with the MCP directory API, please join our Discord server