loaditout.ai
SkillsPacksTrendingLeaderboardAPI DocsBlogSubmitRequestsCompareAgentsXPrivacyDisclaimer
{}loaditout.ai
Skills & MCPPacksBlog

github-security-mcp

MCP Tool

badchars/github-security-mcp

GitHub security posture analysis for AI agents — 39 MCP tools, 45 checks across org, repos, Actions, secrets, supply chain, and access control

Install

$ npx loaditout add badchars/github-security-mcp

Platform-specific configuration:

.claude/settings.json
{
  "mcpServers": {
    "github-security-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "github-security-mcp"
      ]
    }
  }
}

Add the config above to .claude/settings.json under the mcpServers key.

About

<p align="center"> <br> <picture> <source media="(prefers-color-scheme: dark)" srcset="https://raw.githubusercontent.com/badchars/github-security-mcp/main/.github/banner-dark.svg"> <source media="(prefers-color-scheme: light)" srcset="https://raw.githubusercontent.com/badchars/github-security-mcp/main/.github/banner-light.svg"> </picture> </p>

<h3 align="center">GitHub security posture analysis for AI agents.</h3>

<p align="center"> GitHub Enterprise security features cost $21/user/month.<br> This gives your AI agent <b>the same visibility for free</b> — org, repos, Actions, secrets, supply chain. </p>

<br>

<p align="center"> <a href="#the-problem">The Problem</a> &bull; <a href="#how-its-different">How It's Different</a> &bull; <a href="#quick-start">Quick Start</a> &bull; <a href="#what-the-ai-can-do">What The AI Can Do</a> &bull; <a href="#tools-reference-39-tools">Tools</a> &bull; <a href="#check-registry-45-checks">Checks</a> &bull; <a href="#architecture">Architecture</a> </p>

<p align="center"> <a href="LICENSE"></a> </p>

---

The Problem

GitHub security is fragmented. You need separate tools for org settings, repo configurations, Actions workflow analysis, secret scanning, supply chain, and access control. No single tool covers it all, and none work with AI agents.

Traditional workflow:
  manually check org settings        

Tags

access-controlai-agentbranch-protectionbuncodeqldependabotdevsecopsgithub-actionsgithub-apigithub-securityiammcpmcp-servermodel-context-protocolsastsecret-scanningsecurity-auditsupply-chain-securitytypescriptvulnerability-detectiongithubsecurityauditsupply-chain

Reviews

Loading reviews...

Quality Signals

4
Stars
0
Installs
Last updated34 days ago
Security: AREADME

Safety

Risk Levelmedium
Data Access
read
Network Accessnone

Details

Sourcenpm
Last commit3/14/2026
View on GitHub→

Embed Badge

[![Loaditout](https://loaditout.ai/api/badge/badchars/github-security-mcp)](https://loaditout.ai/skills/badchars/github-security-mcp)