Github Extended Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Github Extended Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
An MCP server that extends Claude's GitHub capabilities beyond the standard Docker-based server. Covers gists, starring, profile management, notifications, and other API operations.
The standard GitHub MCP server (ghcr.io/github/github-mcp-server) exposes 26 tools focused on repos, PRs, issues, and code search. This server fills the gaps: gists, starring, profile updates, and notifications.
Use both together for complete GitHub coverage from Claude.
| Tool | Description |
|---|---|
create_gist | Create a public or secret gist |
list_gists | List your gists with pagination |
get_gist | Get a gist with full file contents |
delete_gist | Delete a gist by ID |
star_repo | Star a repository |
unstar_repo | Unstar a repository |
list_starred | List your starred repos |
get_profile | Get your GitHub profile info |
update_profile | Update name, bio, company, location, blog |
list_notifications | List unread notifications |
git clone https://github.com/ZZtopBR/github-extended-mcp.git
cd github-extended-mcp
python3 -m venv venv
source venv/bin/activate # Windows: venv\Scripts\activate
pip install -r requirements.txtCreate a Personal Access Token at github.com/settings/tokens with scopes: gist, user, notifications, read:user.
{
"mcpServers": {
"github-extended": {
"command": "/path/to/venv/bin/python",
"args": ["/path/to/github-extended-mcp/src/server.py"],
"env": { "GITHUB_TOKEN": "ghp_your_token_here" }
}
}
}Run both for full coverage:
{
"mcpServers": {
"github": {
"command": "docker",
"args": ["run", "--rm", "-i", "-e", "GITHUB_PERSONAL_ACCESS_TOKEN", "ghcr.io/github/github-mcp-server"],
"env": { "GITHUB_PERSONAL_ACCESS_TOKEN": "ghp_token" }
},
"github-extended": {
"command": "/path/to/venv/bin/python",
"args": ["/path/to/github-extended-mcp/src/server.py"],
"env": { "GITHUB_TOKEN": "ghp_token" }
}
}
}"Create a gist with my Python snippet"
"List my recent gists"
"Star the repo anthropics/courses"
"Update my GitHub bio"
"Show my unread notifications"MIT
Built with [FastMCP](https://github.com/jlowin/fastmcp) and the [GitHub REST API](https://docs.github.com/en/rest).
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.