New:Socket for Asana Is Now Available.Learn more
Get Started

github-mcp-server-js

Package Overview
Dependencies
Maintainers
1
Versions
8
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

github-mcp-server-js

A GitHub MCP server built on octokit.js and the MCP TypeScript SDK v2 — 104 tools across 16 toolsets, packaged as npm and .mcpb Claude Desktop Extension.

Source
npmnpm
Version
0.1.0
Version published
Weekly downloads
124
42.53%
Maintainers
1
Weekly downloads
 
Created
Source

github-mcp-server-js

A GitHub MCP server built on octokit.js and the MCP TypeScript SDK v2.

Usage

npx github-mcp-server-js

Runs over stdio by default. For a standalone HTTP server:

npx github-mcp-server-js --transport=http --port=3000

Configuration

VariableRequiredDefaultDescription
GITHUB_TOKENYesPersonal access token used for all GitHub API calls
GITHUB_SERVER_URLNogithub.comGitHub host — bare hostname or full API base URL. Set this for GitHub Enterprise Server
GITHUB_PERMISSIONNoread-writeread-only or read-write
LOG_LEVELNoinfodebug, info, or error

Install as a Claude Desktop Extension

Prefer a one-drag install over editing config files? The server also ships as a .mcpb (Claude Desktop Extension) bundle.

  • Download github-mcp-server-js-<version>.mcpb from the latest GitHub Release.
  • Open Claude Desktop → SettingsExtensions.
  • Drag the .mcpb file into the Extensions pane.
  • Fill in your GITHUB_TOKEN (stored in the macOS/Windows keychain — never in plaintext). The other three fields have sensible defaults.
  • Click Install. All 104 tools are now available in every new chat.

To build the bundle locally instead:

npm ci
npm run pack:mcpb
# → dist/github-mcp-server-js-<version>.mcpb

Toolsets

All 16 toolsets from the design are shipped, exposing 104 tools total. Write tools are only registered when GITHUB_PERMISSION=read-write (the default); setting GITHUB_PERMISSION=read-only registers only the read tools. Access column below: R = registered in read-only, W = registered only in read-write.

repos — repositories, branches, commits, tags, file contents

ToolAccessDescription
get_repositoryRGet a GitHub repository by owner and name.
list_branchesRList branches in a repository.
get_branchRGet a single branch in a repository.
get_file_contentsRGet the contents of a file or directory in a repository.
list_commitsRList commits in a repository.
get_commitRGet a single commit in a repository.
list_tagsRList tags in a repository.
create_or_update_fileWCreate a new file or update an existing file in a repository.

issues — issue CRUD, comments, labels, conversation locking

ToolAccessDescription
list_issuesRList issues in a repository.
get_issueRGet a single issue in a repository.
list_commentsRList comments on an issue.
list_labelsRList all labels defined in a repository.
list_labels_on_issueRList the labels currently applied to an issue.
create_issueWCreate a new issue in a repository.
update_issueWUpdate an existing issue.
add_commentWAdd a comment to an issue.
add_labelsWAdd labels to an issue, keeping the issue's existing labels.
remove_labelWRemove a single label from an issue.
lock_issueWLock an issue conversation to collaborators only.
unlock_issueWUnlock a previously locked issue conversation.

pull_requests — PR listing, creation, merging, reviews

ToolAccessDescription
list_pull_requestsRList pull requests in a repository.
get_pull_requestRGet a single pull request.
list_pull_request_filesRList the files changed in a pull request.
list_pull_request_commitsRList the commits on a pull request.
list_pull_request_reviewsRList the reviews on a pull request.
create_pull_requestWCreate a new pull request.
update_pull_requestWUpdate an existing pull request.
merge_pull_requestWMerge a pull request.
create_pull_request_reviewWCreate a review on a pull request.
request_reviewersWRequest reviewers for a pull request.
ToolAccessDescription
search_reposRSearch GitHub repositories. q accepts GitHub search qualifiers (e.g. stars:>100 language:go).
search_codeRSearch code across GitHub. q accepts code-search qualifiers (e.g. repo:foo/bar in:file).
search_commitsRSearch commits on default branches. q accepts commit-search qualifiers.
search_issuesRSearch issues and pull requests (scope with is:issue or is:pull-request).
search_usersRSearch GitHub users.

users — profiles, followers, following, hovercard

ToolAccessDescription
get_user_by_usernameRGet public information about a user by login.
get_authenticated_userRGet the profile of the currently authenticated user (owner of GITHUB_TOKEN).
list_user_followersRList the users who follow a given user.
list_user_followingRList the users that a given user follows.
get_user_hovercardRGet contextual "hovercard" information about a user, optionally scoped to a subject.

gists — list, get, create, update, delete gists

ToolAccessDescription
list_gistsRList gists for the authenticated user.
get_gistRGet a single gist by id (full file content included).
create_gistWCreate a new gist (one or more files, public or secret).
update_gistWUpdate an existing gist: change description, add/rename/delete files.
delete_gistWDelete a gist (permanent — only the owner can delete).

activity — notifications, starred repos, star/unstar

ToolAccessDescription
list_notificationsRList notifications for the authenticated user (paginated, max 50/page).
list_starred_reposRList repositories starred by the authenticated user.
check_repo_starredRCheck whether the authenticated user has starred a repository. Returns { starred: boolean }.
star_repoWStar a repository on behalf of the authenticated user.
unstar_repoWUnstar a repository the authenticated user previously starred.

packages — GitHub Packages owned by the authenticated user

Requires the read:packages token scope. package_type is required and must be one of npm, maven, rubygems, docker, nuget, container.

ToolAccessDescription
list_packages_for_authenticated_userRList packages owned by the authenticated user for a given package type.
get_package_for_authenticated_userRGet a specific package owned by the authenticated user.
list_package_versions_for_authenticated_userRList all versions of a package owned by the authenticated user.
get_package_version_for_authenticated_userRGet a specific version of a package owned by the authenticated user.

misc — utility endpoints

ToolAccessDescription
get_rate_limitRGet the current API rate-limit status for the authenticated user.
get_metaRGet GitHub API metadata: IP ranges, SSH keys, and service host info.
list_emojisRList all emoji names and their image URLs available on GitHub.
render_markdownRRender a Markdown string to HTML using GitHub's renderer (returns raw HTML).

apps — GitHub App public info and user installations

ToolAccessDescription
get_appRGet public metadata for a GitHub App by URL slug.
list_installations_for_authenticated_userRList GitHub App installations accessible to the authenticated user.
list_installation_repos_for_authenticated_userRList repositories the authenticated user can access under a specific installation.

copilot — Copilot org-admin (org-owner PAT required)

ToolAccessDescription
get_copilot_organization_detailsRGet Copilot seat breakdown and policy settings for an organization.
list_copilot_seatsRList all Copilot seat assignments in an organization.
get_copilot_seat_details_for_userRGet Copilot seat details (last activity, editor) for a specific org member.

orgs_teams — organization inspection and team membership

ToolAccessDescription
get_orgRGet a GitHub organization by login.
list_org_membersRList members of an organization.
list_org_reposRList repositories in an organization.
list_teamsRList teams in an organization.
get_team_by_nameRGet a team by its slug within an organization.
list_team_membersRList the members of a team.
add_or_update_team_membershipWAdd a user to a team or update their role (requires org-owner or team-maintainer).
remove_team_membershipWRemove a user from a team (requires org-owner or team-admin).

codespaces — user codespace lifecycle

ToolAccessDescription
list_codespacesRList codespaces for the authenticated user.
get_codespaceRGet a codespace by name for the authenticated user.
create_codespace_in_repoWCreate a codespace in a repository for the authenticated user.
start_codespaceWStart a stopped codespace.
stop_codespaceWStop a running codespace.

projects — GitHub ProjectsV2 (org-scoped, read-only)

ToolAccessDescription
list_org_projectsRList ProjectsV2 projects in an organization.
get_org_projectRGet a ProjectsV2 project by its number.
list_org_project_itemsRList items in a ProjectsV2 project.
list_org_project_fieldsRList fields configured on a ProjectsV2 project.
get_org_project_itemRGet a single item in a ProjectsV2 project.

code_security — code scanning, secrets, Dependabot, advisories

Alert-inspection tools require the security_events PAT scope (or public_repo for public repositories).

ToolAccessDescription
list_code_scanning_alertsRList code-scanning alerts for a repository.
get_code_scanning_alertRGet a code-scanning alert.
list_secret_scanning_alertsRList secret-scanning alerts for a repository.
get_secret_scanning_alertRGet a secret-scanning alert.
list_dependabot_alertsRList Dependabot alerts for a repository.
get_dependabot_alertRGet a Dependabot alert.
list_global_advisoriesRList GitHub Global Security Advisories (public GHSA database).
get_global_advisoryRGet a global GitHub security advisory by GHSA ID.
list_repository_advisoriesRList repository security advisories.
get_repository_advisoryRGet a repository security advisory by GHSA ID.

actions — workflows, runs, jobs, artifacts, check runs

ToolAccessDescription
list_workflowsRList workflows in a repository.
get_workflowRGet a workflow by ID or filename (e.g. ci.yml).
list_workflow_runsRList runs for a workflow (filter by status, branch, event, actor).
get_workflow_runRGet a workflow run by ID.
list_workflow_run_jobsRList jobs for a workflow run.
list_workflow_run_artifactsRList artifacts produced by a workflow run.
list_check_runs_for_refRList check runs for a Git ref (SHA, branch, or tag).
run_workflowWTrigger a workflow_dispatch event for a workflow.
cancel_workflow_runWCancel a workflow run.
rerun_workflow_runWRe-run a workflow run.
rerun_workflow_run_failed_jobsWRe-run only the failed jobs in a workflow run.
approve_workflow_runWApprove a workflow run awaiting fork-PR approval.

See docs/superpowers/specs/2026-08-05-github-mcp-server-design.md for the full architecture.

Testing

Unit tests are hermetic (nock-mocked, no network) and run on every commit:

npm test

Integration tests spawn the built CLI and hit the real GitHub API. They self-skip when GITHUB_TOKEN is missing, so CI without a token stays green.

# Read-only integration suite (safe — no state mutations).
GITHUB_TOKEN=ghp_... npm run test:integration

# Read-only + opt-in write round-trips (create+delete a scratch gist,
# star+unstar a target while restoring the prior state).
GITHUB_TOKEN=ghp_... npm run test:integration:write

The scripts run npm run build first so the tests exercise the built dist/cli.js over stdio, matching real client usage.

Keywords

mcp

FAQs

Package last updated on 06 Aug 2026

Related posts