Skip to main content
Glama
97,619 servers. Updated
20 Best GitHub MCP Servers: compared and ranked, October 2026Ranked from 1,788 matching servers on stars, growth, downloads and maintenance. Updated .

Matching MCP tools:

Matching MCP Connectors:

"GitHub Actions" matching MCP servers:

GET /v1/servers – MCP directory API reference
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables scanning GitHub Actions workflow YAML for real-world security vulnerabilities such as script injection from attacker-controlled expressions, unpinned third-party actions, missing permissions blocks, and dangerous pull_request_target checkouts. It returns each finding with its exact location, an explanation of the risk, and a concrete remediation.
    MIT
  • F
    license
    Not graded
    quality
    D
    maintenance
    Audits GitHub Actions workflow files for supply-chain risks like script injection, leaked tokens, unpinned actions, and broad permissions.
    -
  • A
    license
    A
    quality
    B
    maintenance
    Enables reviewing GitHub Actions workflows for outdated actions, deprecated Node runtimes, retired runners, deprecated commands, and security risks, with file, line, and fix for each finding.
    3
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    Scans GitHub Actions workflow files for dangerous triggers, template injection, unpinned actions, excessive permissions, and secrets in shell commands before they are committed, exposing the checks as MCP tools for agents.
    2
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    An MCP server that enables AI agents to perform comprehensive GitHub security audits across org settings, repositories, Actions workflows, secrets, supply chain, and access control using 39 tools and 45 checks.
    39
    162 npm
    15
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    A lightweight stdio-to-http relay that enables the GitHub MCP server to authenticate using a GitHub App instead of a Personal Access Token. It automatically manages fine-grained permissions and short-lived tokens for secure, organizational AI agent workflows.
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    Scans diffs, files, and snippets for leaked secrets like AWS keys, GitHub tokens, and private keys, returning redacted findings while running fully locally without network calls.
    1
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    A secure MCP server for querying a subscription business database with AST-based SQL guarding, PII masking, audited two-step write actions, and a seeded demo dataset.
    8
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    Enables MCP-capable agents to gate their actions behind human consent, checking consent rules and requesting approval via Telegram before proceeding with high-stakes operations.
    2
    30 npm
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    Provides tools to issue, verify, and export cryptographically signed receipts for AI agent actions, enabling tamper-proof audit trails for compliance with regulations like the EU AI Act.
    4
    74 npm
    1
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    MCP server that gives AI agents paid tools to de-risk costly actions: dependency vetting, x402 endpoint verification, JSON repair, and URL reading. Fronts the Guard HTTP API at guard.fabtally.com.
    4
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Enables AI assistants to monitor GitHub repository health by calculating health scores, fetching repository metadata, analyzing Dependabot alerts, checking CI/CD status, and retrieving code scanning alerts.
    8
    240 npm
    1
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    Enables LLMs to access realtime CVE intelligence aggregated from NVD, CISA KEV, EPSS, GitHub advisories, PoC discovery, and Metasploit/Nuclei tooling, providing vulnerability details, exploitation signals, and prioritized triage verdicts.
    12
    14 npm
    2
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    Biometric authorization for AI agent actions via Face ID on iPhone, enabling secure approval of sensitive actions and credential-safe API calls through vault execution.
    7
    MIT
  • F
    license
    A
    quality
    D
    maintenance
    Governance circuit-breaker MCP server that enables AI agents to request risk-based decisions, approve or deny actions, and finalize outcomes with full audit receipts.
    4
    -