GHAS MCP server (GitHub Advanced Security)
Server Quality Checklist
Latest release: v1.0.0
- Disambiguation5/5
Each tool has a clearly distinct purpose targeting different types of GitHub Advanced Security alerts: code scanning, Dependabot, and secret scanning. The descriptions explicitly differentiate the alert types, leaving no ambiguity about which tool to use for each security domain.
Naming Consistency5/5All tools follow a perfect verb_noun pattern with 'list_' prefix followed by the specific alert type (code_scanning_alerts, dependabot_alerts, secret_scanning_alerts). The naming is completely consistent across all three tools with no deviations in style or structure.
Tool Count3/5With only 3 tools, the server feels quite thin for GitHub Advanced Security's scope, which includes multiple security domains and potential operations beyond just listing alerts. While the tools cover the core alert types, the count is borderline minimal for what could be a more comprehensive security management interface.
Completeness2/5The toolset is severely incomplete for GitHub Advanced Security operations. While it covers listing three types of alerts, there are significant gaps: no ability to create, update, dismiss, or resolve alerts; no access to security overviews or metrics; and no coverage of other GHAS features like code scanning analyses or security advisories. This creates dead ends for agents needing to take action on security findings.
Average 2.9/5 across 3 of 3 tools scored.
See the Tool Scores section below for per-tool breakdowns.
This repository is archived. Archived repositories automatically receive an F maintenance tier.
This repository is licensed under MIT License.
This repository includes a README.md file.
No tool usage detected in the last 30 days. Usage tracking helps demonstrate server value.
Tip: use the "Try in Browser" feature on the server page to seed initial usage.
Add a glama.json file to provide metadata about your server.
If you are the author, simply .
If the server belongs to an organization, first add
glama.jsonto the root of your repository:{ "$schema": "https://glama.ai/mcp/schemas/server.json", "maintainers": [ "your-github-username" ] }Then . Browse examples.
Add related servers to improve discoverability.
How to sync the server with GitHub?
Servers are automatically synced at least once per day, but you can also sync manually at any time to instantly update the server profile.
To manually sync the server, click the "Sync Server" button in the MCP server admin interface.
How is the quality score calculated?
The overall quality score combines two components: Tool Definition Quality (70%) and Server Coherence (30%).
Tool Definition Quality measures how well each tool describes itself to AI agents. Every tool is scored 1–5 across six dimensions: Purpose Clarity (25%), Usage Guidelines (20%), Behavioral Transparency (20%), Parameter Semantics (15%), Conciseness & Structure (10%), and Contextual Completeness (10%). The server-level definition quality score is calculated as 60% mean TDQS + 40% minimum TDQS, so a single poorly described tool pulls the score down.
Server Coherence evaluates how well the tools work together as a set, scoring four dimensions equally: Disambiguation (can agents tell tools apart?), Naming Consistency, Tool Count Appropriateness, and Completeness (are there gaps in the tool surface?).
Tiers are derived from the overall score: A (≥3.5), B (≥3.0), C (≥2.0), D (≥1.0), F (<1.0). B and above is considered passing.
Tool Scores
- Behavior2/5
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden of behavioral disclosure. It states the tool lists alerts but does not describe key traits like whether it requires authentication, has rate limits, returns paginated results, or what the output format is. This leaves significant gaps in understanding how the tool behaves.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Conciseness5/5Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single, clear sentence that efficiently conveys the core purpose without unnecessary words. It is appropriately sized and front-loaded, making it easy to understand at a glance.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Completeness2/5Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's complexity (listing security alerts), lack of annotations, no output schema, and low parameter schema coverage, the description is incomplete. It does not provide enough context on behavior, output, or parameter usage, making it inadequate for effective tool invocation.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Parameters2/5Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema has 2 parameters with 0% description coverage, so the schema provides no semantic information. The description does not add any meaning to the parameters (owner, repo), such as explaining what they represent or how to format them, failing to compensate for the low schema coverage.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Purpose4/5Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the action ('List') and the resource ('GitHub Advanced Security secret scanning alerts for a repository'), making the purpose specific and understandable. However, it does not explicitly differentiate from sibling tools like 'list_code_scanning_alerts' or 'list_dependabot_alerts', which would be needed for a score of 5.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Usage Guidelines2/5Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides no guidance on when to use this tool versus alternatives, such as the sibling tools listed. It mentions the context ('for a repository') but lacks explicit when/when-not instructions or comparisons to other alert-listing tools, leaving usage unclear.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
- Behavior2/5
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden of behavioral disclosure. It mentions 'List the current... alerts' but does not specify whether this is a read-only operation, if it requires authentication, rate limits, pagination, or what the output format entails. This leaves significant gaps in understanding the tool's behavior.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Conciseness5/5Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single, efficient sentence that directly states the tool's purpose without unnecessary words. It is front-loaded and appropriately sized, making it easy to parse quickly.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Completeness2/5Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's complexity (listing security alerts), lack of annotations, and no output schema, the description is incomplete. It does not cover behavioral aspects like permissions, response format, or error handling, which are crucial for effective use. The description alone is insufficient for an agent to fully understand how to invoke and interpret results.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Parameters3/5Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema has 0% description coverage, but the description does not add any meaning to the parameters 'owner' and 'repo' beyond implying they relate to a GitHub repository. Since there are only 2 parameters, the baseline is 4, but the description fails to compensate for the lack of schema details, such as explaining what 'owner' and 'repo' represent, resulting in a score of 3.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Purpose4/5Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the verb ('List') and resource ('GitHub Advanced Security code scanning alerts for a repository'), making the tool's purpose specific and understandable. However, it does not explicitly differentiate from sibling tools like 'list_dependabot_alerts' or 'list_secret_scanning_alerts', which prevents a score of 5.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Usage Guidelines2/5Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides no guidance on when to use this tool versus alternatives, such as the sibling tools for Dependabot or secret scanning alerts. It lacks any context about prerequisites, exclusions, or specific scenarios where this tool is preferred, offering only a basic statement of function.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
- Behavior2/5
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full burden of behavioral disclosure. It states the tool lists alerts but does not describe key behaviors like whether it requires authentication, rate limits, pagination, or what the output format looks like. For a tool with zero annotation coverage, this lack of detail is a significant gap, warranting a score of 2.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Conciseness5/5Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single, efficient sentence: 'List the current GitHub Dependabot alerts for a repository.' It is front-loaded with the core action and resource, with no wasted words or unnecessary details. This makes it highly concise and well-structured, earning a score of 5.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Completeness2/5Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's complexity (listing security alerts), lack of annotations, and no output schema, the description is incomplete. It does not cover behavioral aspects like authentication needs, rate limits, or output format, which are crucial for an AI agent to use the tool effectively. With these gaps, the description falls short of being fully helpful, resulting in a score of 2.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Parameters3/5Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema has 2 parameters (owner and repo) with 0% description coverage, meaning the schema provides no semantic details. The description does not add any parameter-specific information, such as explaining what 'owner' and 'repo' refer to or their expected formats. Since the description does not compensate for the low schema coverage, the baseline score of 3 is applied, as it neither adds value nor fully addresses the gap.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Purpose4/5Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose: 'List the current GitHub Dependabot alerts for a repository.' It specifies the verb ('List'), resource ('GitHub Dependabot alerts'), and scope ('for a repository'), which is specific and actionable. However, it does not explicitly differentiate from sibling tools like 'list_code_scanning_alerts' or 'list_secret_scanning_alerts', which reduces the score from a 5 to a 4.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Usage Guidelines2/5Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides no guidance on when to use this tool versus alternatives. It does not mention sibling tools or any context for choosing this tool over others, such as for dependency-related security issues. Without explicit usage instructions or exclusions, the score is a 2, as it offers minimal guidance beyond the basic purpose.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
GitHub Badge
Glama performs regular codebase and documentation scans to:
- Confirm that the MCP server is working as expected.
- Confirm that there are no obvious security issues.
- Evaluate tool definition quality.
Our badge communicates server capabilities, safety, and installation instructions.
Card Badge
Copy to your README.md:
Score Badge
Copy to your README.md:
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/rajbos/ghas-mcp-server'
If you have feedback or need assistance with the MCP directory API, please join our Discord server