MCP Security Index

Is GitHub safe to install?

GitHub · Dev tools · Streamable HTTP

unrated exposure

Could not reach this server

AxioRank could not enumerate GitHub's surface (live handshake failed (HTTP 401 Unauthorized from https://api.githubcopilot.com/mcp/); no usable well-known card (HTTP 404 fetching https://api.githubcopilot.com/.well-known/mcp.json)). It stays unrated until the next scan succeeds.

View the source

Embed your grade

AxioRank MCP Security Index grade for GitHub

Drop this in your README or registry listing. It links back to this page and updates whenever the grade changes.

[![AxioRank MCP Security Index grade for GitHub](https://axiorank.com/api/badge/mcp/github.svg)](https://axiorank.com/mcp-index/github)

This grade reflects the blast radius of what GitHub declares it can do, read-only, not whether it is secure or trustworthy. Maintain this server? Claim this listing or request a re-scan. Learn how grades are computed on the index overview.

Let your agents use GitHub safely

Route this server through AxioRank to allowlist its tools, block risky calls, and keep an audit trail of every action.

Start free