Official agent skill

GitHub MCP Server

by github in github/gh-aw

Reference for GitHub MCP server tools, methods, and usage patterns.

OfficialMITAuto-check passedAgent Workflows

Install GitHub MCP Server

skills CLI
$ npx skills add github/gh-aw --skill github-mcp-server -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install github/gh-aw github-mcp-server --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/github/gh-aw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/github-mcp-server .claude/skills/github-mcp-server && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
github-mcp-server
GitHub stars
5.3k
Token cost
~4.8k tokens
SKILL.md length
2,135 words
Files
1
Skills in repo
52
Repo updated
First seen
Licence
MIT

At a glance

Reference for GitHub MCP server tools, methods, and usage patterns.

  • Works in 4 steps: Start with defaults: For most workflows,… → Enable specific toolsets: Only enable… → Security consideration: Be mindful of… → …
  • Tasks that involve MCP servers
  • SKILL.md covers Overview, Configuration, Available Toolsets and Available Tools by Toolset, plus 2 more sections
  • Calls gh; reaches github.com and api.githubcopilot.com; needs GITHUB_TOKEN and GITHUB_PERSONAL_ACCESS_TOKEN

What it does

GitHub MCP Server is an agent skill from github/gh-aw, published by the product's own GitHub organization. Reference for GitHub MCP server tools, methods, and usage patterns.

Its SKILL.md is about 4.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Agent Workflows, covering MCP servers. It works with GitHub, Model Context Protocol and Docker. The repository describes itself as: GitHub Agentic Workflows. The licence is MIT.

When your agent uses it

  • Tasks that involve MCP servers

Example prompts

  • “/github-mcp-server”

Requirements

  • Docker
  • A credential in GITHUB_PERSONAL_ACCESS_TOKEN
  • A credential in GH_AW_GITHUB_TOKEN

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Start with defaults: For most workflows, the recommended default toolsets provide sufficient functionality
  2. Enable specific toolsets: Only enable additional toolsets when you need their specific functionality
  3. Security consideration: Be mindful of write operations - consider using read-only mode when possible
  4. Performance: Using fewer toolsets reduces initialization time and memory usage

What it can do on your machine

Read from SKILL.md and the folder at commit eb63040. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com
    • api.githubcopilot.com

    Also links to:

    • modelcontextprotocol.io
    • docs.github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GITHUB_TOKEN
    • GITHUB_PERSONAL_ACCESS_TOKEN
    • GH_AW_GITHUB_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

GitHub MCP Server loads about 4.8k tokens when it runs. Until then it costs about 21 tokens; SKILL.md has 2,135 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~21
When it runs · the whole SKILL.md, loaded when a task matches
~4.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from github/gh-aw at commit eb63040, republished under its MIT licence (© github). 2,135 words, ~4,793 tokens.

Download SKILL.mdSave it as .claude/skills/github-mcp-server/SKILL.md (or your agent's skills folder).
name
github-mcp-server
description
Reference for GitHub MCP server tools, methods, and usage patterns.

GitHub MCP Server Documentation

This file documents the GitHub MCP (Model Context Protocol) server, including tools and configuration options.

Note: This file is automatically generated and updated by the github-mcp-tools-report.md workflow. Manual edits may be overwritten.

Last Updated: [To be filled by workflow]

Overview

The GitHub MCP server provides AI agents with programmatic access to GitHub's API through the Model Context Protocol. It supports two modes of operation:

Local Mode (Docker-based)
  • Runs as a Docker container on the GitHub Actions runner
  • Uses GITHUB_PERSONAL_ACCESS_TOKEN environment variable for authentication
  • Configurable toolsets via GITHUB_TOOLSETS environment variable
  • Supports read-only mode via GITHUB_READ_ONLY environment variable
Remote Mode (Hosted)
  • Connects to hosted GitHub MCP server at https://api.githubcopilot.com/mcp/
  • Uses Bearer token authentication in HTTP headers
  • Supports read-only mode via X-MCP-Readonly header
  • No Docker container required

Configuration

Basic Configuration

Local Mode (Docker):

yaml
tools:
  github:
    mode: "local"
    toolsets: [default]  # or [repos, issues, pull_requests]

Remote Mode (Hosted):

yaml
tools:
  github:
    mode: "remote"
    toolsets: [default]  # or [repos, issues, pull_requests]
Read-Only Mode

To restrict the GitHub MCP server to read-only operations:

yaml
tools:
  github:
    mode: "remote"
    read-only: true
    toolsets: [repos, issues]
Custom Authentication

Use a custom GitHub token instead of the default:

yaml
tools:
  github:
    mode: "remote"
    github-token: "${{ secrets.CUSTOM_GITHUB_PAT }}"
    toolsets: [repos, issues]

Available Toolsets

The GitHub MCP server organizes tools into logical toolsets. You can enable specific toolsets, use [default] for the recommended defaults, or use [all] to enable everything.

:::note[Why Use Toolsets?] The allowed: pattern for listing individual GitHub tools is not recommended for new workflows. Individual tool names may change between GitHub MCP server versions, but toolsets provide a stable API. Always use toolsets: instead. See Migration from Allowed to Toolsets for guidance on updating existing workflows. :::

:::tip[Best Practice] Always use toolsets: for GitHub tools. Toolsets provide:

  • Stability: Tool names may change between MCP server versions, but toolsets remain stable
  • Better organization: Clear groupings of related functionality
  • Complete functionality: Get all related tools automatically
  • Reduced verbosity: Cleaner configuration
  • Future-proof: New tools are automatically included as they're added :::

The following toolsets are enabled by default when toolsets: is not specified:

  • context - User and environment context (strongly recommended)
  • repos - Repository management
  • issues - Issue management
  • pull_requests - Pull request operations

Note: The users toolset is not included by default and must be explicitly specified if needed.

All Available Toolsets
ToolsetDescriptionCommon Tools
contextUser and environment contextget_teams, get_team_members
reposRepository managementget_repository, get_file_contents, search_code, list_commits
issuesIssue managementissue_read, list_issues, create_issue, search_issues
pull_requestsPull request operationspull_request_read, list_pull_requests, create_pull_request
actionsGitHub Actions/CI/CDlist_workflows, list_workflow_runs, download_workflow_run_artifact
code_securityCode scanning and securitylist_code_scanning_alerts ⚠️ (always include state: open and severity: critical,high), get_code_scanning_alert
dependabotDependency managementDependabot alerts and updates
discussionsGitHub Discussionslist_discussions, create_discussion
experimentsExperimental featuresUnstable/preview APIs
gistsGist operationscreate_gist, list_gists
labelsLabel managementget_label, list_labels, create_label
notificationsNotificationslist_notifications, mark_notifications_read
orgsOrganization managementget_organization, list_organizations
projectsGitHub ProjectsProject board operations
secret_protectionSecret scanningSecret detection and management
security_advisoriesSecurity advisoriesAdvisory creation and management
stargazersRepository starsStar-related operations
usersUser profilesget_me ⚠️ (see note below), get_user, list_users
searchAdvanced searchSearch across repos, code, users

:::caution[get_me returns 403 under the integration token] get_me is not recommended in agentic workflows. It returns HTTP 403 when called under the GitHub Actions integration token (which is the default in all gh-aw runs). Do not call get_me to determine the agent's identity.

Canonical identity source: The <github-context> block is injected at the start of every workflow prompt and contains actor, repository, run_id, and other context values. Always read identity from there. :::

Available Tools by Toolset

This section maps individual tools to their respective toolsets to help with migration from allowed: to toolsets:.

Context Toolset
  • get_teams - List teams the user belongs to
  • get_team_members - List members of a specific team
Repos Toolset
  • get_repository - Get repository information
  • get_file_contents - Read file contents from repository
  • search_code - Search code across repositories
  • list_commits - List commits in a repository
  • get_commit - Get details of a specific commit
  • get_latest_release - Get the latest release
  • list_releases - List all releases
Issues Toolset
  • issue_read - Read issue details
  • list_issues - List issues in a repository
  • create_issue - Create a new issue
  • update_issue - Update an existing issue
  • search_issues - Search issues across repositories
  • add_reaction - Add reaction to an issue or comment
  • create_issue_comment - Add a comment to an issue
Pull Requests Toolset
  • pull_request_read - Read pull request details
  • list_pull_requests - List pull requests in a repository
  • get_pull_request - Get details of a specific pull request
  • create_pull_request - Create a new pull request
  • search_pull_requests - Search pull requests across repositories

When invoking list_pull_requests from workflow prompts/templates:

  • Default to a small page size (perPage: 10 unless a smaller/larger value is justified).
  • On GitHub MCP server ≥ 1.6.0 with the fields_param feature (enabled automatically in Insiders mode), pass fields: [number, title, state, html_url] (or whichever top-level fields you need) to reduce response size. The same fields parameter is available on list_issues, search_issues, search_pull_requests, list_commits, list_releases, and search_code. For get_file_contents, fields only reduces directory listings; use fields: [name, type, size, path] to check file metadata before deciding whether to read a file.
  • Before using get_file_contents on a file, list its parent directory with fields: [name, type, size, path]. If the file is large or you only need a header/section, use a bounded excerpt such as a raw file URL with an HTTP range or another available ranged-read tool instead of fetching the whole file.
  • On older servers, request minimal_output: true when the installed MCP server exposes that input (minimal output trims non-essential nested fields such as large head/base payloads).
  • Confirm parameter support in the method schema from mcp list-tools or the tool docs for your server version.
Actions Toolset
  • list_workflows - List GitHub Actions workflows
  • list_workflow_runs - List workflow runs
  • get_workflow_run - Get details of a specific workflow run
  • download_workflow_run_artifact - Download workflow artifacts
Code Security Toolset
  • list_code_scanning_alerts - List code scanning alerts
  • get_code_scanning_alert - Get details of a specific alert
  • create_code_scanning_alert - Create a code scanning alert

When invoking list_code_scanning_alerts from workflow prompts/templates, always include state: open and severity: critical,high to bound the response size and avoid oversized payloads.

Discussions Toolset
  • list_discussions - List discussions in a repository
  • create_discussion - Create a new discussion
Labels Toolset
  • get_label - Get label details
  • list_labels - List labels in a repository
  • create_label - Create a new label
Users Toolset
  • get_me - ⚠️ Not recommended — returns HTTP 403 under the integration token. Use the <github-context> block (provided at the start of every prompt) to read your identity: actor, repository, run_id, etc.
  • get_user - Get user profile information
  • list_users - List users
Notifications Toolset
  • list_notifications - List user notifications
  • mark_notifications_read - Mark notifications as read
Organizations Toolset
  • get_organization - Get organization details
  • list_organizations - List organizations
Gists Toolset
  • create_gist - Create a new gist
  • list_gists - List user's gists

Authentication Details

Remote Mode Authentication

The remote mode uses Bearer token authentication:

Headers:

  • Authorization: Bearer <token> - Required for authentication
  • X-MCP-Readonly: true - Optional, enables read-only mode

Token Source:

  • Default: ${{ secrets.GH_AW_GITHUB_TOKEN }} or ${{ secrets.GITHUB_TOKEN }}
  • Custom: Configure via github-token field
Local Mode Authentication

The local mode uses environment variables:

Environment Variables:

  • GITHUB_PERSONAL_ACCESS_TOKEN - Required for authentication
  • GITHUB_READ_ONLY=1 - Optional, enables read-only mode
  • GITHUB_TOOLSETS=<comma-separated-list> - Optional, specifies enabled toolsets

Best Practices

Toolset Selection
  1. Start with defaults: For most workflows, the recommended default toolsets provide sufficient functionality
  2. Enable specific toolsets: Only enable additional toolsets when you need their specific functionality
  3. Security consideration: Be mindful of write operations - consider using read-only mode when possible
  4. Performance: Using fewer toolsets reduces initialization time and memory usage
Token Permissions

Ensure your GitHub token has appropriate permissions for the toolsets you're enabling:

  • repos toolsets: Requires repository read/write permissions
  • issues toolsets: Requires issues read/write permissions
  • pull_requests toolsets: Requires pull requests read/write permissions
  • actions toolsets: Requires actions read/write permissions
  • discussions toolsets: Requires discussions read/write permissions
Remote vs Local Mode

Use Remote Mode when:

  • You want faster initialization (no Docker container to start)
  • You're running in a GitHub Actions environment with internet access
  • You want to use the latest version without specifying Docker image tags

Use Local Mode when:

  • You need a specific version of the MCP server
  • You want to use custom arguments
  • You're running in an environment without internet access
  • You want to test with a local build of the MCP server
Show full SKILL.md (852 more words)Show less

Migration from Allowed to Toolsets

If you have existing workflows using the allowed: pattern, we recommend migrating to toolsets: for better maintainability and stability. Individual tool names may change between MCP server versions, but toolsets provide a stable API that won't break your workflows.

Migration Examples

Using allowed: (not recommended):

yaml
tools:
  github:
    allowed:
      - get_repository
      - get_file_contents
      - list_commits
      - list_issues
      - create_issue
      - update_issue

Using toolsets: (recommended):

yaml
tools:
  github:
    toolsets: [repos, issues]
Tool-to-Toolset Mapping

Use this table to identify which toolset contains the tools you need:

allowed: ToolsMigrate to toolsets:
get_me ⚠️ (not recommended — returns 403; use <github-context> instead)users
get_teams, get_team_memberscontext
get_repository, get_file_contents, search_code, list_commitsrepos
issue_read, list_issues, create_issue, update_issue, search_issuesissues
pull_request_read, list_pull_requests, create_pull_requestpull_requests
list_workflows, list_workflow_runs, get_workflow_runactions
list_code_scanning_alerts ⚠️ (always include state: open and severity: critical,high), get_code_scanning_alertcode_security
list_discussions, create_discussiondiscussions
get_label, list_labels, create_labellabels
get_user, list_usersusers
Mixed repos/issues/PRs tools[default]
All tools[all]
Quick Migration Steps
  1. Identify tools in use: Review your current allowed: list
  2. Map to toolsets: Use the table above to find corresponding toolsets
  3. Replace configuration: Change allowed: to toolsets:
  4. Test: Run gh aw mcp inspect <workflow> to verify tools are available
  5. Compile: Run gh aw compile to update the lock file

Using Allowed Pattern with Custom MCP Servers

:::note[When to Use Allowed] The allowed: pattern is appropriate for:

  • Custom MCP servers (non-GitHub)
  • Gradual migration of existing workflows
  • Fine-grained restriction of specific tools within a toolset

For GitHub tools, always use toolsets: instead of allowed:. :::

The allowed: field can still be used to restrict tools for custom MCP servers:

yaml
mcp-servers:
  notion:
    container: "mcp/notion"
    allowed: ["search_pages", "get_page"]  # Fine for custom MCP servers

For GitHub tools, allowed: can be combined with toolsets: to further restrict access, but this pattern is not recommended for new workflows.

GitHub API Limitations

Not all GitHub data is accessible through the GitHub MCP server or the GitHub REST API. Be aware of these limitations when designing workflows to avoid silent failures or incomplete results at runtime.

Billing and Cost Data

❌ Not available via standard API permissions:

  • Detailed per-run cost data — GitHub Actions does not expose per-workflow-run billing costs through the REST API. There is no endpoint to retrieve the exact cost of a specific workflow run.
  • Actions billing summary — Billing endpoints (e.g., /orgs/{org}/settings/billing/actions) require admin:org scope, which is not granted by actions:read or the default GITHUB_TOKEN.

⚠️ When suggesting billing/cost workflows, always note:

Detailed GitHub Actions billing and cost data is not accessible through the standard GitHub API with actions:read permissions. Workflows that attempt to read per-run cost data or billing summaries will fail silently or return empty results unless an admin:org-scoped personal access token is explicitly configured.

✅ Alternatives for cost reporting:

  1. GitHub Actions usage reports — Download usage reports from the GitHub billing UI (Settings → Billing → Usage) or via the billing CSV export endpoint (requires admin:org scope with a PAT).
  2. Billing settings UI — Direct users to https://github.com/organizations/{org}/settings/billing or https://github.com/settings/billing for personal accounts to view cost data manually.
  3. Workflow run metadata — Use list_workflow_runs and get_workflow_run (available via actions toolset) to get run duration, status, and timing — but not dollar costs.
  4. Third-party cost tracking — Integrate with third-party CI cost tools that use pre-authorized API access.
Cross-Organization Data Access

❌ Not available without explicit authorization:

  • Workflows can only access data from repositories and organizations that the configured GitHub token has been granted access to.
  • Cross-organization repository reads require a PAT or GitHub App token with access to the target org — the default GITHUB_TOKEN is scoped to the current repository's organization only.
  • Organization membership and team data from other organizations is not accessible without explicit read:org permissions on those organizations.
Organization Membership and Private Data

❌ Requires additional scopes:

  • Organization member lists — Reading private organization membership requires read:org scope; the default GITHUB_TOKEN only exposes public membership.
  • Private repository contents — Only accessible if the token has explicit repository access.
  • Secret values — GitHub Secrets are write-only through the API; their values cannot be read back after creation.
Rate Limits

⚠️ Be aware of API rate limits:

  • The GitHub REST API enforces rate limits (typically 5,000 requests/hour for authenticated requests with a PAT, lower for GITHUB_TOKEN).
  • Workflows that perform bulk data collection (e.g., listing all workflow runs across many repositories) may hit rate limits. Design workflows to paginate carefully and avoid unnecessary requests.
  • GraphQL API has separate rate limits based on query complexity.

Troubleshooting

Common Issues

Issue: Tool not found or not available

  • Solution: Check if you're using allowed: to restrict tools. Consider using toolsets: instead to get all related tools.
  • Verify: Run gh aw mcp inspect <workflow-name> to see which tools are actually available.

Issue: Missing functionality after specifying toolset

  • Cause: Using a too-narrow toolset that doesn't include all needed tools
  • Solution: Either add additional toolsets (e.g., toolsets: [default, actions]) or use [all] for full access

Issue: Workflow using allowed: list is verbose and hard to maintain

  • Solution: Migrate to toolsets: configuration using the migration guide above
Best Practices for Debugging
  1. Start with [default] toolset: Most workflows work well with default toolsets
  2. Add specific toolsets as needed: Incrementally add toolsets like actions, discussions, etc.
  3. Use gh aw mcp inspect: Verify which tools are actually available
  4. Check tool-to-toolset mapping: Reference the tables above to find the right toolset

References

© github, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/github-mcp-server of github/gh-aw.

Open the folder on GitHubat commit eb63040

Compare with similar skills

GitHub MCP Server next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

GitHub MCP Server compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
GitHub MCP Server this skillgithub/gh-aw5.3k—~4.8kAutomated safety check: PassMIT
Project Releaseswimmwatch/cloakbrowser-mcp161—~1.9kAutomated safety check: PassMIT
Devcontainer Devstacklok/toolhive-studio170—~3.8kAutomated safety check: NotesApache-2.0
MCP Registryvibeeval/vibecosystem531—~1.3kAutomated safety check: NotesMIT
Project Pull Requestswimmwatch/cloakbrowser-mcp161—~1kAutomated safety check: PassMIT
Skill Seekers Builderyusufkaraaslan/Skill_Seekers15k—~760Automated safety check: PassMIT

Similar skills

  • Project Release

    swimmwatch/cloakbrowser-mcp

    Prepare, publish, verify, or recover a cloakbrowser-mcp release only when the user explicitly requests release work.

    161 GitHub stars~1.9k tokensUpdated 5 days ago
    Agent WorkflowsAuto-check passed
  • Devcontainer Dev

    stacklok/toolhive-studio

    Spin up and interact with ToolHive Studio's containerized dev environment (Xvfb + noVNC + DinD).

    170 GitHub stars~3.8k tokensUpdated today
    Agent WorkflowsAuto-check: notes
  • MCP Registry

    vibeeval/vibecosystem

    MCP server registry, auto-discovery, configuration, custom server development guide

    531 GitHub stars~1.3k tokensUpdated 1 mo ago
    Agent WorkflowsAuto-check: notes
  • Project Pull Request

    swimmwatch/cloakbrowser-mcp

    Create, update, prepare, or review a cloakbrowser-mcp GitHub Pull Request only when the user explicitly requests PR work.

    161 GitHub stars~1k tokensUpdated 5 days ago
    DevelopmentAuto-check passed
  • Skill Seekers Builder

    yusufkaraaslan/Skill_Seekers

    Detects the type of a knowledge source and uses the Skill Seekers MCP tools to turn docs, repos, PDFs or videos into packaged AI skills.

    15k GitHub stars~760 tokensUpdated 6 days ago
    Agent WorkflowsAuto-check passed
  • MCP Apps Builder

    awslabs/cli-agent-orchestrator

    Official

    Load the official MCP Apps builder skills (create-mcp-app, migrate-oai-app, add-app-to-server, convert-web-app) from github.com/modelcontextprotocol/ext-apps.

    1.4k GitHub stars~1.7k tokensUpdated today
    Agent WorkflowsAuto-check passed

More from github/gh-aw

All 52 skills in this repo
  • Official

    Drives a real browser from the command line with playwright-cli to open pages, interact, mock requests, save state and work with Playwright tests.

    5.3k GitHub starsUsed in 23 repos~2.8k tokens
    Auto-check passed
  • Official

    Designs and verifies a deterministic grader that measures whether a GitHub Agentic Workflow run reached its real-world or repository outcome.

    5.3k GitHub stars~6.8k tokensUpdated today
    Auto-check passed
  • Official

    Scaffolds, edits, reloads and debugs a canvas extension that the GitHub Copilot CLI can open in its side panel.

    5.3k GitHub stars~3.7k tokensUpdated today
    Auto-check passed
  • Official

    Drives an open pull request to merge-ready from inside a GitHub Copilot cloud agent, resolving review threads and local checks concurrently, without merging or retriggering CI.

    5.3k GitHub stars~3.8k tokensUpdated today
    Auto-check: warnings
  • Official

    Bumps gh-aw's pinned gh-aw-firewall version, rebuilds generated artifacts, and flags upstream spec or schema changes that need follow-up work.

    5.3k GitHub stars~899 tokensUpdated today
    Auto-check passed
  • Official

    Guide to the console struct tag system in gh-aw: headers, titles, number and cost formats, omitempty, and how structs, slices and maps render in the terminal.

    5.3k GitHub stars~736 tokensUpdated today
    Auto-check passed

Categories

Questions about GitHub MCP Server

What does GitHub MCP Server do?

Reference for GitHub MCP server tools, methods, and usage patterns. GitHub MCP Server is an agent skill from github/gh-aw, published by the product's own GitHub organization. Reference for GitHub MCP server tools, methods, and usage patterns.

When should I use GitHub MCP Server?

GitHub MCP Server fits situations like: tasks that involve MCP servers.

How do I install GitHub MCP Server in Claude Code?

Run `npx skills add github/gh-aw --skill github-mcp-server -a claude-code`. Or copy the skill folder (.github/skills/github-mcp-server in github/gh-aw) into .claude/skills/github-mcp-server in your project. Claude Code loads it when a task matches its description.

How do I install GitHub MCP Server in Codex?

Run `npx skills add github/gh-aw --skill github-mcp-server -a codex`. Or copy the skill folder (.github/skills/github-mcp-server in github/gh-aw) into .agents/skills/github-mcp-server in your project. Codex loads it when a task matches its description.

Can I use GitHub MCP Server in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add github/gh-aw --skill github-mcp-server -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/github-mcp-server, .gemini/skills/github-mcp-server, .github/skills/github-mcp-server and .opencode/skills/github-mcp-server in your project.

What does GitHub MCP Server need to run?

Going by SKILL.md and its folder, GitHub MCP Server needs the command-line tools its instructions call (gh) and credentials named GITHUB_TOKEN, GITHUB_PERSONAL_ACCESS_TOKEN and GH_AW_GITHUB_TOKEN. Our summary lists: Docker; A credential in GITHUB_PERSONAL_ACCESS_TOKEN; A credential in GH_AW_GITHUB_TOKEN.

Does GitHub MCP Server access the network?

SKILL.md names 4 domains. In commands or code: github.com and api.githubcopilot.com; the agent is likely to contact these when it follows the instructions. As links in the text: modelcontextprotocol.io and docs.github.com. This is read from the text; nothing was executed.

Is GitHub MCP Server safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does GitHub MCP Server use?

GitHub MCP Server is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does GitHub MCP Server use?

About 4.8k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to GitHub MCP Server?

Skills that share tags, products or a category with GitHub MCP Server: Project Release (swimmwatch/cloakbrowser-mcp, 161 stars), Devcontainer Dev (stacklok/toolhive-studio, 170 stars), MCP Registry (vibeeval/vibecosystem, 531 stars) and Project Pull Request (swimmwatch/cloakbrowser-mcp, 161 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains GitHub MCP Server?

github (a GitHub organization, an official publisher) maintains it in github/gh-aw, which has 5,350 GitHub stars. The repository holds 52 skills in this directory. The repository was last updated on October 7, 2026.

Source: github/gh-aw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.