Back to skill

Security audit

github-mcp

Security checks for vulnerabilities and agentic risk

Overview

This GitHub skill appears purpose-built, but it needs review because it recommends a remote GitHub MCP endpoint with a bearer token and documents repository-changing actions without clear safety boundaries.

Review this before installing. Use a narrowly scoped GitHub token, prefer the local stdio server for sensitive or private repositories, and require explicit confirmation before creating, editing, deleting, posting, triggering workflows, or creating repositories through the skill.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

External Transmission

Medium
Category
Data Exfiltration
Confidence
78% confidence
Finding

Referencing an external MCP endpoint means the skill may transmit user requests and GitHub-derived data outside the local environment. In context this is expected functionality, but it still creates a real exposure surface because the description does not bound what may be sent or warn about privacy implications.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: github-mcp
description: Use the GitHub MCP server (github-mcp-server) to browse repositories, manage issues and PRs, analyze code, search files, monitor CI/CD workflows, and automate GitHub operations. Triggers when user asks to search code, manage GitHub issues/PRs, view commits, analyze repository structure, check CI/CD status, fork repos, create branches, or any GitHub-related operations that require API access. Works with local stdio-based github-mcp-server binary or remote HTTP endpoint (https://api.githubcopilot.com/mcp/).
---

# GitHub MCP Skill

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger description is broad enough to activate on many generic GitHub-related requests, which can cause the skill to be invoked in situations the user may not expect. Because this skill can access repositories, issues, PRs, workflows, and branch/fork operations, overbroad activation increases the chance of unintended data access or side-effecting actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill recommends a remote HTTP mode using an Authorization bearer token but does not clearly warn that repository data, prompts, and credentials are being sent to an external service endpoint. Users may assume GitHub operations are local or first-party-safe without understanding the data exposure, which is especially risky for private repositories and sensitive metadata.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The example command sends a GitHub bearer token to a remote HTTP endpoint, creating direct credential and data-exposure risk if the endpoint, transport configuration, logs, or surrounding environment are mishandled. Marking this remote mode as 'Recommended' without a prominent warning makes unsafe deployment more likely, especially for private-repo access.

Content

Scanner excerpt · SKILL.md (reported line 15)May include surrounding context.

Remote Server (HTTP) — Recommended

bash
mcporter config add github --type http --url "https://api.githubcopilot.com/mcp/" --header "Authorization=Bearer ${GITHUB_TOKEN}"

Local Stdio Server

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation includes state-changing GitHub operations such as creating pull requests and adding review comments without any warning that these actions modify repository state and may have external effects. In an agent skill context, this increases the chance that an agent will invoke write-capable tools during ambiguous user requests, leading to unintended repository changes, spam, or workflow side effects.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.