Project Release
swimmwatch/cloakbrowser-mcp
Prepare, publish, verify, or recover a cloakbrowser-mcp release only when the user explicitly requests release work.
Reference for GitHub MCP server tools, methods, and usage patterns.
$ npx skills add github/gh-aw --skill github-mcp-server -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install github/gh-aw github-mcp-server --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/github/gh-aw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/github-mcp-server .claude/skills/github-mcp-server && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "github-mcp-server" agent skill from https://github.com/github/gh-aw/tree/main/.github/skills/github-mcp-server into .claude/skills/github-mcp-server/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-mcp-server", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/github/gh-aw/tree/main/.github/skills/github-mcp-serverType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add github/gh-aw --skill github-mcp-server -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install github/gh-aw github-mcp-server --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/gh-aw.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.github/skills/github-mcp-server .agents/skills/github-mcp-server && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "github-mcp-server" agent skill from https://github.com/github/gh-aw/tree/main/.github/skills/github-mcp-server into .agents/skills/github-mcp-server/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-mcp-server", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add github/gh-aw --skill github-mcp-server -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install github/gh-aw github-mcp-server --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/gh-aw.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.github/skills/github-mcp-server .cursor/skills/github-mcp-server && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "github-mcp-server" agent skill from https://github.com/github/gh-aw/tree/main/.github/skills/github-mcp-server into .cursor/skills/github-mcp-server/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-mcp-server", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/github/gh-aw.git --path .github/skills/github-mcp-server--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add github/gh-aw --skill github-mcp-server -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install github/gh-aw github-mcp-server --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/gh-aw.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.github/skills/github-mcp-server .gemini/skills/github-mcp-server && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "github-mcp-server" agent skill from https://github.com/github/gh-aw/tree/main/.github/skills/github-mcp-server into .gemini/skills/github-mcp-server/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-mcp-server", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install github/gh-aw github-mcp-serverInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add github/gh-aw --skill github-mcp-server -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/github/gh-aw.git skills-src && mkdir -p .github/skills && cp -r skills-src/.github/skills/github-mcp-server .github/skills/github-mcp-server && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "github-mcp-server" agent skill from https://github.com/github/gh-aw/tree/main/.github/skills/github-mcp-server into .github/skills/github-mcp-server/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-mcp-server", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add github/gh-aw --skill github-mcp-server -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install github/gh-aw github-mcp-server --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/gh-aw.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.github/skills/github-mcp-server .opencode/skills/github-mcp-server && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "github-mcp-server" agent skill from https://github.com/github/gh-aw/tree/main/.github/skills/github-mcp-server into .opencode/skills/github-mcp-server/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-mcp-server", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
github-mcp-serverReference for GitHub MCP server tools, methods, and usage patterns.
GitHub MCP Server is an agent skill from github/gh-aw, published by the product's own GitHub organization. Reference for GitHub MCP server tools, methods, and usage patterns.
Its SKILL.md is about 4.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Agent Workflows, covering MCP servers. It works with GitHub, Model Context Protocol and Docker. The repository describes itself as: GitHub Agentic Workflows. The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit eb63040. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
ghFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comapi.githubcopilot.comAlso links to:
modelcontextprotocol.iodocs.github.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
GITHUB_TOKENGITHUB_PERSONAL_ACCESS_TOKENGH_AW_GITHUB_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
GitHub MCP Server loads about 4.8k tokens when it runs. Until then it costs about 21 tokens; SKILL.md has 2,135 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from github/gh-aw at commit eb63040, republished under its MIT licence (© github). 2,135 words, ~4,793 tokens.
.claude/skills/github-mcp-server/SKILL.md (or your agent's skills folder).This file documents the GitHub MCP (Model Context Protocol) server, including tools and configuration options.
Note: This file is automatically generated and updated by the github-mcp-tools-report.md workflow. Manual edits may be overwritten.
Last Updated: [To be filled by workflow]
The GitHub MCP server provides AI agents with programmatic access to GitHub's API through the Model Context Protocol. It supports two modes of operation:
GITHUB_PERSONAL_ACCESS_TOKEN environment variable for authenticationGITHUB_TOOLSETS environment variableGITHUB_READ_ONLY environment variablehttps://api.githubcopilot.com/mcp/X-MCP-Readonly headerLocal Mode (Docker):
tools:
github:
mode: "local"
toolsets: [default] # or [repos, issues, pull_requests]Remote Mode (Hosted):
tools:
github:
mode: "remote"
toolsets: [default] # or [repos, issues, pull_requests]To restrict the GitHub MCP server to read-only operations:
tools:
github:
mode: "remote"
read-only: true
toolsets: [repos, issues]Use a custom GitHub token instead of the default:
tools:
github:
mode: "remote"
github-token: "${{ secrets.CUSTOM_GITHUB_PAT }}"
toolsets: [repos, issues]The GitHub MCP server organizes tools into logical toolsets. You can enable specific toolsets, use [default] for the recommended defaults, or use [all] to enable everything.
:::note[Why Use Toolsets?]
The allowed: pattern for listing individual GitHub tools is not recommended for new workflows. Individual tool names may change between GitHub MCP server versions, but toolsets provide a stable API. Always use toolsets: instead. See Migration from Allowed to Toolsets for guidance on updating existing workflows.
:::
:::tip[Best Practice]
Always use toolsets: for GitHub tools. Toolsets provide:
The following toolsets are enabled by default when toolsets: is not specified:
context - User and environment context (strongly recommended)repos - Repository managementissues - Issue management pull_requests - Pull request operationsNote: The users toolset is not included by default and must be explicitly specified if needed.
| Toolset | Description | Common Tools |
|---|---|---|
context | User and environment context | get_teams, get_team_members |
repos | Repository management | get_repository, get_file_contents, search_code, list_commits |
issues | Issue management | issue_read, list_issues, create_issue, search_issues |
pull_requests | Pull request operations | pull_request_read, list_pull_requests, create_pull_request |
actions | GitHub Actions/CI/CD | list_workflows, list_workflow_runs, download_workflow_run_artifact |
code_security | Code scanning and security | list_code_scanning_alerts ⚠️ (always include state: open and severity: critical,high), get_code_scanning_alert |
dependabot | Dependency management | Dependabot alerts and updates |
discussions | GitHub Discussions | list_discussions, create_discussion |
experiments | Experimental features | Unstable/preview APIs |
gists | Gist operations | create_gist, list_gists |
labels | Label management | get_label, list_labels, create_label |
notifications | Notifications | list_notifications, mark_notifications_read |
orgs | Organization management | get_organization, list_organizations |
projects | GitHub Projects | Project board operations |
secret_protection | Secret scanning | Secret detection and management |
security_advisories | Security advisories | Advisory creation and management |
stargazers | Repository stars | Star-related operations |
users | User profiles | get_me ⚠️ (see note below), get_user, list_users |
search | Advanced search | Search across repos, code, users |
:::caution[get_me returns 403 under the integration token]
get_me is not recommended in agentic workflows. It returns HTTP 403 when called under the GitHub Actions integration token (which is the default in all gh-aw runs). Do not call get_me to determine the agent's identity.
Canonical identity source: The <github-context> block is injected at the start of every workflow prompt and contains actor, repository, run_id, and other context values. Always read identity from there.
:::
This section maps individual tools to their respective toolsets to help with migration from allowed: to toolsets:.
get_teams - List teams the user belongs toget_team_members - List members of a specific teamget_repository - Get repository informationget_file_contents - Read file contents from repositorysearch_code - Search code across repositorieslist_commits - List commits in a repositoryget_commit - Get details of a specific commitget_latest_release - Get the latest releaselist_releases - List all releasesissue_read - Read issue detailslist_issues - List issues in a repositorycreate_issue - Create a new issueupdate_issue - Update an existing issuesearch_issues - Search issues across repositoriesadd_reaction - Add reaction to an issue or commentcreate_issue_comment - Add a comment to an issuepull_request_read - Read pull request detailslist_pull_requests - List pull requests in a repositoryget_pull_request - Get details of a specific pull requestcreate_pull_request - Create a new pull requestsearch_pull_requests - Search pull requests across repositoriesWhen invoking list_pull_requests from workflow prompts/templates:
perPage: 10 unless a smaller/larger value is justified).fields_param feature (enabled automatically in Insiders mode), pass fields: [number, title, state, html_url] (or whichever top-level fields you need) to reduce response size. The same fields parameter is available on list_issues, search_issues, search_pull_requests, list_commits, list_releases, and search_code. For get_file_contents, fields only reduces directory listings; use fields: [name, type, size, path] to check file metadata before deciding whether to read a file.get_file_contents on a file, list its parent directory with fields: [name, type, size, path]. If the file is large or you only need a header/section, use a bounded excerpt such as a raw file URL with an HTTP range or another available ranged-read tool instead of fetching the whole file.minimal_output: true when the installed MCP server exposes that input (minimal output trims non-essential nested fields such as large head/base payloads).mcp list-tools or the tool docs for your server version.list_workflows - List GitHub Actions workflowslist_workflow_runs - List workflow runsget_workflow_run - Get details of a specific workflow rundownload_workflow_run_artifact - Download workflow artifactslist_code_scanning_alerts - List code scanning alertsget_code_scanning_alert - Get details of a specific alertcreate_code_scanning_alert - Create a code scanning alertWhen invoking list_code_scanning_alerts from workflow prompts/templates, always include state: open and severity: critical,high to bound the response size and avoid oversized payloads.
list_discussions - List discussions in a repositorycreate_discussion - Create a new discussionget_label - Get label detailslist_labels - List labels in a repositorycreate_label - Create a new labelget_me - ⚠️ Not recommended — returns HTTP 403 under the integration token. Use the <github-context> block (provided at the start of every prompt) to read your identity: actor, repository, run_id, etc.get_user - Get user profile informationlist_users - List userslist_notifications - List user notificationsmark_notifications_read - Mark notifications as readget_organization - Get organization detailslist_organizations - List organizationscreate_gist - Create a new gistlist_gists - List user's gistsThe remote mode uses Bearer token authentication:
Headers:
Authorization: Bearer <token> - Required for authenticationX-MCP-Readonly: true - Optional, enables read-only modeToken Source:
${{ secrets.GH_AW_GITHUB_TOKEN }} or ${{ secrets.GITHUB_TOKEN }}github-token fieldThe local mode uses environment variables:
Environment Variables:
GITHUB_PERSONAL_ACCESS_TOKEN - Required for authenticationGITHUB_READ_ONLY=1 - Optional, enables read-only modeGITHUB_TOOLSETS=<comma-separated-list> - Optional, specifies enabled toolsetsEnsure your GitHub token has appropriate permissions for the toolsets you're enabling:
repos toolsets: Requires repository read/write permissionsissues toolsets: Requires issues read/write permissionspull_requests toolsets: Requires pull requests read/write permissionsactions toolsets: Requires actions read/write permissionsdiscussions toolsets: Requires discussions read/write permissionsUse Remote Mode when:
Use Local Mode when:
If you have existing workflows using the allowed: pattern, we recommend migrating to toolsets: for better maintainability and stability. Individual tool names may change between MCP server versions, but toolsets provide a stable API that won't break your workflows.
Using allowed: (not recommended):
tools:
github:
allowed:
- get_repository
- get_file_contents
- list_commits
- list_issues
- create_issue
- update_issueUsing toolsets: (recommended):
tools:
github:
toolsets: [repos, issues]Use this table to identify which toolset contains the tools you need:
allowed: Tools | Migrate to toolsets: |
|---|---|
get_me ⚠️ (not recommended — returns 403; use <github-context> instead) | users |
get_teams, get_team_members | context |
get_repository, get_file_contents, search_code, list_commits | repos |
issue_read, list_issues, create_issue, update_issue, search_issues | issues |
pull_request_read, list_pull_requests, create_pull_request | pull_requests |
list_workflows, list_workflow_runs, get_workflow_run | actions |
list_code_scanning_alerts ⚠️ (always include state: open and severity: critical,high), get_code_scanning_alert | code_security |
list_discussions, create_discussion | discussions |
get_label, list_labels, create_label | labels |
get_user, list_users | users |
| Mixed repos/issues/PRs tools | [default] |
| All tools | [all] |
allowed: listallowed: to toolsets:gh aw mcp inspect <workflow> to verify tools are availablegh aw compile to update the lock file:::note[When to Use Allowed]
The allowed: pattern is appropriate for:
For GitHub tools, always use toolsets: instead of allowed:.
:::
The allowed: field can still be used to restrict tools for custom MCP servers:
mcp-servers:
notion:
container: "mcp/notion"
allowed: ["search_pages", "get_page"] # Fine for custom MCP serversFor GitHub tools, allowed: can be combined with toolsets: to further restrict access, but this pattern is not recommended for new workflows.
Not all GitHub data is accessible through the GitHub MCP server or the GitHub REST API. Be aware of these limitations when designing workflows to avoid silent failures or incomplete results at runtime.
❌ Not available via standard API permissions:
/orgs/{org}/settings/billing/actions) require admin:org scope, which is not granted by actions:read or the default GITHUB_TOKEN.⚠️ When suggesting billing/cost workflows, always note:
Detailed GitHub Actions billing and cost data is not accessible through the standard GitHub API with
actions:readpermissions. Workflows that attempt to read per-run cost data or billing summaries will fail silently or return empty results unless anadmin:org-scoped personal access token is explicitly configured.
✅ Alternatives for cost reporting:
admin:org scope with a PAT).https://github.com/organizations/{org}/settings/billing or https://github.com/settings/billing for personal accounts to view cost data manually.list_workflow_runs and get_workflow_run (available via actions toolset) to get run duration, status, and timing — but not dollar costs.❌ Not available without explicit authorization:
GITHUB_TOKEN is scoped to the current repository's organization only.read:org permissions on those organizations.❌ Requires additional scopes:
read:org scope; the default GITHUB_TOKEN only exposes public membership.⚠️ Be aware of API rate limits:
GITHUB_TOKEN).Issue: Tool not found or not available
allowed: to restrict tools. Consider using toolsets: instead to get all related tools.gh aw mcp inspect <workflow-name> to see which tools are actually available.Issue: Missing functionality after specifying toolset
toolsets: [default, actions]) or use [all] for full accessIssue: Workflow using allowed: list is verbose and hard to maintain
toolsets: configuration using the migration guide above[default] toolset: Most workflows work well with default toolsetsactions, discussions, etc.gh aw mcp inspect: Verify which tools are actually available© github, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .github/skills/github-mcp-server of github/gh-aw.
Open the folder on GitHubat commit eb63040
GitHub MCP Server next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| GitHub MCP Server this skillgithub/gh-aw | 5.3k | — | ~4.8k | Automated safety check: Pass | MIT | |
| Project Releaseswimmwatch/cloakbrowser-mcp | 161 | — | ~1.9k | Automated safety check: Pass | MIT | |
| Devcontainer Devstacklok/toolhive-studio | 170 | — | ~3.8k | Automated safety check: Notes | Apache-2.0 | |
| MCP Registryvibeeval/vibecosystem | 531 | — | ~1.3k | Automated safety check: Notes | MIT | |
| Project Pull Requestswimmwatch/cloakbrowser-mcp | 161 | — | ~1k | Automated safety check: Pass | MIT | |
| Skill Seekers Builderyusufkaraaslan/Skill_Seekers | 15k | — | ~760 | Automated safety check: Pass | MIT |
swimmwatch/cloakbrowser-mcp
Prepare, publish, verify, or recover a cloakbrowser-mcp release only when the user explicitly requests release work.
stacklok/toolhive-studio
Spin up and interact with ToolHive Studio's containerized dev environment (Xvfb + noVNC + DinD).
vibeeval/vibecosystem
MCP server registry, auto-discovery, configuration, custom server development guide
swimmwatch/cloakbrowser-mcp
Create, update, prepare, or review a cloakbrowser-mcp GitHub Pull Request only when the user explicitly requests PR work.
yusufkaraaslan/Skill_Seekers
Detects the type of a knowledge source and uses the Skill Seekers MCP tools to turn docs, repos, PDFs or videos into packaged AI skills.
awslabs/cli-agent-orchestrator
Load the official MCP Apps builder skills (create-mcp-app, migrate-oai-app, add-app-to-server, convert-web-app) from github.com/modelcontextprotocol/ext-apps.
github/gh-aw
Drives a real browser from the command line with playwright-cli to open pages, interact, mock requests, save state and work with Playwright tests.
github/gh-aw
Designs and verifies a deterministic grader that measures whether a GitHub Agentic Workflow run reached its real-world or repository outcome.
github/gh-aw
Scaffolds, edits, reloads and debugs a canvas extension that the GitHub Copilot CLI can open in its side panel.
github/gh-aw
Drives an open pull request to merge-ready from inside a GitHub Copilot cloud agent, resolving review threads and local checks concurrently, without merging or retriggering CI.
github/gh-aw
Bumps gh-aw's pinned gh-aw-firewall version, rebuilds generated artifacts, and flags upstream spec or schema changes that need follow-up work.
github/gh-aw
Guide to the console struct tag system in gh-aw: headers, titles, number and cost formats, omitempty, and how structs, slices and maps render in the terminal.
Works with
Categories
Reference for GitHub MCP server tools, methods, and usage patterns. GitHub MCP Server is an agent skill from github/gh-aw, published by the product's own GitHub organization. Reference for GitHub MCP server tools, methods, and usage patterns.
GitHub MCP Server fits situations like: tasks that involve MCP servers.
Run `npx skills add github/gh-aw --skill github-mcp-server -a claude-code`. Or copy the skill folder (.github/skills/github-mcp-server in github/gh-aw) into .claude/skills/github-mcp-server in your project. Claude Code loads it when a task matches its description.
Run `npx skills add github/gh-aw --skill github-mcp-server -a codex`. Or copy the skill folder (.github/skills/github-mcp-server in github/gh-aw) into .agents/skills/github-mcp-server in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add github/gh-aw --skill github-mcp-server -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/github-mcp-server, .gemini/skills/github-mcp-server, .github/skills/github-mcp-server and .opencode/skills/github-mcp-server in your project.
Going by SKILL.md and its folder, GitHub MCP Server needs the command-line tools its instructions call (gh) and credentials named GITHUB_TOKEN, GITHUB_PERSONAL_ACCESS_TOKEN and GH_AW_GITHUB_TOKEN. Our summary lists: Docker; A credential in GITHUB_PERSONAL_ACCESS_TOKEN; A credential in GH_AW_GITHUB_TOKEN.
SKILL.md names 4 domains. In commands or code: github.com and api.githubcopilot.com; the agent is likely to contact these when it follows the instructions. As links in the text: modelcontextprotocol.io and docs.github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
GitHub MCP Server is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.8k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with GitHub MCP Server: Project Release (swimmwatch/cloakbrowser-mcp, 161 stars), Devcontainer Dev (stacklok/toolhive-studio, 170 stars), MCP Registry (vibeeval/vibecosystem, 531 stars) and Project Pull Request (swimmwatch/cloakbrowser-mcp, 161 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
github (a GitHub organization, an official publisher) maintains it in github/gh-aw, which has 5,350 GitHub stars. The repository holds 52 skills in this directory. The repository was last updated on October 7, 2026.
Source: github/gh-aw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.