From d3cca91908954263c75d2709e1fffb459c69a8d0 Mon Sep 17 00:00:00 2001 From: Christoph Blecker Date: Thu, 24 Sep 2026 14:35:24 -0700 Subject: [PATCH] feat(github): replace broad MCP toolsets with a curated tool allowlist Scope the GitHub MCP server to the tools actually used across recent sessions, dropping repository-mutating writes, merges, workflow triggers, and unused toolsets (discussions, labels, projects, orgs, secret protection, copilot) to shrink the prompt-injection blast radius. Assisted-by: LLM --- github/.claude-plugin/plugin.json | 4 +-- github/.mcp.json | 3 +- github/README.md | 47 ++++++++++++++++++++----------- 3 files changed, 35 insertions(+), 19 deletions(-) diff --git a/github/.claude-plugin/plugin.json b/github/.claude-plugin/plugin.json index fc4eb5d..c12083d 100644 --- a/github/.claude-plugin/plugin.json +++ b/github/.claude-plugin/plugin.json @@ -1,7 +1,7 @@ { "name": "github", - "description": "GitHub MCP server with selected toolsets for repository management, code security, discussions, notifications, and more.", - "version": "1.4.1", + "description": "GitHub MCP server with a curated tool allowlist for pull requests, issues, notifications, read-only repository access, and code security.", + "version": "1.5.0", "author": { "name": "cblecker", "email": "admin@toph.ca" diff --git a/github/.mcp.json b/github/.mcp.json index f6a6645..efa8baa 100644 --- a/github/.mcp.json +++ b/github/.mcp.json @@ -5,7 +5,8 @@ "url": "https://api.githubcopilot.com/mcp/", "headers": { "Authorization": "Bearer ${GITHUB_PERSONAL_ACCESS_TOKEN}", - "X-MCP-Toolsets": "default,actions,orgs,labels,notifications,discussions,gists,projects,code_security,secret_protection,dependabot,security_advisories,github_support_docs_search" + "X-MCP-Toolsets": "gists,code_security,security_advisories,dependabot,github_support_docs_search", + "X-MCP-Tools": "actions_get,actions_list,get_job_logs,get_file_contents,search_code,list_commits,get_commit,list_releases,list_tags,get_latest_release,get_release_by_tag,get_tag,search_repositories,search_commits,list_branches,pull_request_read,search_pull_requests,list_pull_requests,create_pull_request,update_pull_request,pull_request_review_write,add_comment_to_pending_review,add_reply_to_pull_request_comment,issue_read,search_issues,list_issues,issue_write,add_issue_comment,update_issue_comment,sub_issue_write,list_issue_types,list_issue_fields,get_me,get_teams,get_team_members,search_users,list_notifications,get_notification_details,dismiss_notification,manage_notification_subscription,check_dependency_vulnerabilities" } } } diff --git a/github/README.md b/github/README.md index 71833f0..d050973 100644 --- a/github/README.md +++ b/github/README.md @@ -1,26 +1,41 @@ # GitHub Plugin -GitHub MCP server with selected toolsets enabled for repository management, code security, discussions, notifications, and more. +GitHub MCP server with a curated tool allowlist for pull requests, issues, notifications, read-only repository access, and code security. ## Components ### MCP Server -HTTP-based MCP server connected to `api.githubcopilot.com`. Tools are deferred and loaded on demand via tool search, keeping them out of the context window until needed. The following toolsets are enabled: - -- `default` — repos, issues, pull requests, commits, files, users -- `actions` — workflow runs, jobs, artifacts, logs -- `orgs` — organization membership and teams -- `labels` — repository label management -- `notifications` — notification listing and management -- `discussions` — repository discussions and comments -- `gists` — gist creation and management -- `projects` — GitHub Projects (v2) management -- `code_security` — code scanning alerts -- `secret_protection` — secret scanning alerts -- `dependabot` — Dependabot alerts -- `security_advisories` — global and repository security advisories -- `github_support_docs_search` — GitHub product documentation search +HTTP-based MCP server connected to `api.githubcopilot.com`. Tools are deferred and loaded on demand via tool search, keeping them out of the context window until needed. + +The server is configured with two headers in `.mcp.json`: + +- `X-MCP-Toolsets` enables these toolsets in full, including tools added to them upstream: + - `gists` — gist reading, creation, and updates + - `code_security` — code scanning alerts + - `security_advisories` — global and repository security advisories + - `dependabot` — Dependabot alerts + - `github_support_docs_search` — GitHub product documentation search (remote-only) +- `X-MCP-Tools` adds individual tools on top. Because the `default` toolset is not + named, nothing else is enabled — new upstream tools in these areas require an + explicit opt-in: + - **Pull requests** — `pull_request_read`, `search_pull_requests`, `list_pull_requests`, + `create_pull_request`, `update_pull_request`, `pull_request_review_write`, + `add_comment_to_pending_review`, `add_reply_to_pull_request_comment` + - **Issues** — `issue_read`, `search_issues`, `list_issues`, `issue_write`, + `add_issue_comment`, `update_issue_comment`, `sub_issue_write`, `list_issue_types`, + `list_issue_fields` + - **Repositories (read-only)** — `get_file_contents`, `search_code`, `search_repositories`, + `list_branches`, `list_commits`, `get_commit`, `search_commits`, `list_tags`, `get_tag`, + `list_releases`, `get_latest_release`, `get_release_by_tag` + - **Actions (read-only)** — `actions_list`, `actions_get`, `get_job_logs` + - **Notifications** — `list_notifications`, `get_notification_details`, + `dismiss_notification`, `manage_notification_subscription` + - **Users and teams** — `get_me`, `get_teams`, `get_team_members`, `search_users` + - **Other** — `check_dependency_vulnerabilities` (remote-only) + +To enable another tool, add its exact name to `X-MCP-Tools`; an unknown name +causes the server to reject the connection. ### Hooks