External Transmission
- Category
- Data Exfiltration
- Confidence
- 78% confidence
- Finding
Referencing an external MCP endpoint means the skill may transmit user requests and GitHub-derived data outside the local environment. In context this is expected functionality, but it still creates a real exposure surface because the description does not bound what may be sent or warn about privacy implications.
- Content
md --- name: github-mcp description: Use the GitHub MCP server (github-mcp-server) to browse repositories, manage issues and PRs, analyze code, search files, monitor CI/CD workflows, and automate GitHub operations. Triggers when user asks to search code, manage GitHub issues/PRs, view commits, analyze repository structure, check CI/CD status, fork repos, create branches, or any GitHub-related operations that require API access. Works with local stdio-based github-mcp-server binary or remote HTTP endpoint (https://api.githubcopilot.com/mcp/). --- # GitHub MCP Skill
