Github Repo Intel Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Github Repo Intel Mcp (Agent Skill) and scored it 96/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 1 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A hosted Model Context Protocol server that gives AI coding agents structured intelligence about any GitHub repository — overview, recent PRs, contributors, hot files, CI status, and dependencies — through a single MCP endpoint.
No local setup. No `git clone`. No Octokit boilerplate. Plug your agent into the MCP URL and start asking questions.
Local GitHub MCP servers exist, but they require every user to set up Node/Python, install the server, manage tokens, and keep it patched. This Actor runs on Apify's platform and is reachable as a hosted streamable-HTTP MCP endpoint — your agent just needs the URL.
It's useful when you want an LLM to reason about a codebase without giving it filesystem or shell access: think code-review bots, repo-onboarding helpers, dependency-audit agents, refactor planners.
| This Actor | Local MCP server | |
|---|---|---|
| Setup | Paste URL + token into client config | git clone, install deps, manage Node/Python versions |
| Distribution | Same URL works for every teammate | Each teammate sets up their own |
| Updates | Always latest server build | You patch + redeploy |
| Auth surface | One Apify token + optional GitHub PAT in tool args | GitHub PAT lives on every machine |
| Cost when idle | $0 (Standby mode, billed per call) | Whatever your laptop/server costs |
| When local wins | Air-gapped repos, on-prem GitHub Enterprise | — |
get_contributors + list_recent_prs + get_hot_files on the target repo to know who you're dealing with and where the churn actually lives.get_dependencies across a list of repos in a loop, no shell access required, no risk of malicious npm install running on your machine.| Tool | What it returns | Typical use |
|---|---|---|
get_repo_overview | Stars, forks, language, license, topics, last push | "Is this repo still maintained?" |
list_recent_prs | Recent PRs with author, state, merge dates | "Show me the last 20 merged PRs by user X" |
get_contributors | Top contributors by commit count | "Who maintains this project?" |
get_hot_files | Most-modified files over the last N commits | "Where's the churn?" |
get_ci_status | Check runs and conclusions for a ref | "Is the default branch green?" |
get_dependencies | Parses package.json, requirements.txt, go.mod, Cargo.toml, pyproject.toml | "What does this project depend on?" |
Every tool accepts an optional github_token parameter. With no token you get GitHub's 60-req/hour limit on public repos. Provide a fine-grained PAT and you get 5,000 req/hour and can access private repos.
$0.005 per tool call. First 100 calls free per user.
Pay-per-event model — you only pay when a tool actually executes. No subscription, no minimums. The server runs in Apify Standby mode, so you're not billed for idle time.
The Actor exposes a Streamable-HTTP MCP transport at:
https://cg-nguyen--github-repo-intel-mcp.apify.actor/mcpAuthentication uses your Apify token via the Authorization: Bearer <APIFY_TOKEN> header — most MCP clients let you configure this in their server config.
curl -X POST https://cg-nguyen--github-repo-intel-mcp.apify.actor/mcp \
-H "Authorization: Bearer <APIFY_TOKEN>" \
-H "Content-Type: application/json" \
-H "Accept: application/json, text/event-stream" \
-d '{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/call",
"params": {
"name": "get_repo_overview",
"arguments": {"owner": "facebook", "repo": "react"}
}
}'{
"mcpServers": {
"github-repo-intel": {
"url": "https://cg-nguyen--github-repo-intel-mcp.apify.actor/mcp",
"headers": {
"Authorization": "Bearer <APIFY_TOKEN>"
}
}
}
}get_hot_files tool scans up to 200 commits and makes one API call per commit, so it eats GitHub rate limit the fastest. Pass a github_token if you call it often.get_ci_status reads the GitHub Checks API — it surfaces GitHub Actions, CodeQL, and any third-party check that posts back via the Checks API. Repos that run their CI entirely on external systems (Prow, Buildkite, CircleCI without GitHub integration) may show 0 check runs even when the build is green. The response includes a note field flagging this case.Author: luongnp. Open to feature requests — file an issue on the Actor page if you want a tool added (issues board, releases, dependency vulnerabilities via Dependabot API, etc.).
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.