Problem
The local GitHub MCP can already read CodeQL/code-scanning alerts, secret-scanning alerts, Dependabot alerts, Actions, rulesets and repository security advisories, but it cannot currently verify several repository-level security/settings flags used in our audits.
This forces a fallback to gh api/PowerShell for settings such as:
security_and_analysis.secret_scanning.status
security_and_analysis.secret_scanning_push_protection.status
- Private Vulnerability Reporting enabled/disabled
delete_branch_on_merge
has_issues
Desired capability
Add a narrow read-only MCP tool that returns repository security/settings status for one repository.
Suggested output should include, when the GitHub API exposes them:
- repository visibility
- default branch
- Issues enabled
- auto-delete head branches
- Secret Scanning status
- Secret Scanning Push Protection status
- Private Vulnerability Reporting status
- whether a setting is unavailable because the token lacks permission vs genuinely disabled
The tool should not mutate repository settings.
Permission model
Use the existing runtime PAT first. If GitHub requires additional permission, the minimal target is read-only administration/security metadata (for example Administration: read on a fine-grained PAT), not Administration: write.
Do not create a new token unless the existing token cannot be extended safely.
Security constraints
- Preserve the existing DPAPI -> stdin -> tmpfs PAT path.
- Never expose the PAT, token scopes, credentials or secret material in tool output.
- Keep the gateway/tool policy narrow; adding this read-only status capability must not open a generic arbitrary REST proxy.
- Distinguish API permission errors (
403/unsupported endpoint) from an actual disabled feature.
Acceptance criteria
- ChatGPT can query one allowlisted/accessible repository and obtain the settings above without PowerShell.
- Missing GitHub permission is reported explicitly rather than converted to
false/disabled.
- Existing security tests remain green.
- No repository mutation capability is added.
- README/tool documentation explains any required GitHub token permission.
Problem
The local GitHub MCP can already read CodeQL/code-scanning alerts, secret-scanning alerts, Dependabot alerts, Actions, rulesets and repository security advisories, but it cannot currently verify several repository-level security/settings flags used in our audits.
This forces a fallback to
gh api/PowerShell for settings such as:security_and_analysis.secret_scanning.statussecurity_and_analysis.secret_scanning_push_protection.statusdelete_branch_on_mergehas_issuesDesired capability
Add a narrow read-only MCP tool that returns repository security/settings status for one repository.
Suggested output should include, when the GitHub API exposes them:
The tool should not mutate repository settings.
Permission model
Use the existing runtime PAT first. If GitHub requires additional permission, the minimal target is read-only administration/security metadata (for example
Administration: readon a fine-grained PAT), notAdministration: write.Do not create a new token unless the existing token cannot be extended safely.
Security constraints
403/unsupported endpoint) from an actual disabled feature.Acceptance criteria
false/disabled.