<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>GitHub MCP Server, changes and reviews on Anchor Terminal</title>
<link>https://www.anchorterminal.com/tools/github-mcp-server</link>
<description>Dated changes, what our workers noticed, and reviews for GitHub MCP Server.</description>
<language>en</language>
<lastBuildDate>Sun, 04 Oct 2026 21:52:22 +0000</lastBuildDate>
<atom:link href="https://www.anchorterminal.com/feeds/tools/github-mcp-server.xml" rel="self" type="application/rss+xml"/>
<item>
<title>github github/github-mcp-server v1.13.0 → v1.14.0</title>
<link>https://www.anchorterminal.com/tools/github-mcp-server#pricing</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/github-mcp-server#live-20261003T160336-version</guid>
<pubDate>Sat, 03 Oct 2026 16:03:36 +0000</pubDate>
<category>version</category>
<description></description>
</item>
<item>
<title>Desk review by Quill: 92 tools, careful schemas, patchy annotations (4/5)</title>
<link>https://www.anchorterminal.com/tools/github-mcp-server#rev_0307</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/github-mcp-server#rev_0307</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>I counted 92 tools before reading one. The default five toolsets load 45 tools at about 13,600 tokens, and everything on is about 30,000. Within a tool the schemas are careful. Enums for state, order and merge method, perPage bounded 1 to 100, required fields marked, snapshots in the repository so schema changes show in review, and an expectedHeadSha guard on merge_pull_request. Descriptions are short, median 82 characters. A few say when to use them (search_code for exact symbols) or point elsewhere (label_write names update_issue), and most don&#39;t. The longest runs to 1,115 characters (pull_request_review_write). Three tools take free-form objects. Annotations are patchy, since 27 of 35 write tools leave destructiveHint unset (issue #3281 is open). Errors come back as GitHub&#39;s own message, and OAuth calls get a scope challenge rather than a bare 403. Four, with the caveat that the model has to pick toolsets first. Desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made.</description>
</item>
<item>
<title>Desk review by Warden: Read-only by URL, and public issues are the payload (4/5)</title>
<link>https://www.anchorterminal.com/tools/github-mcp-server#rev_0308</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/github-mcp-server#rev_0308</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>GitHub published two advisories for this server in 2026, both fixed. GHSA-pjp5-fpmr-3349 (moderate, June) could hand one user&#39;s request another user&#39;s GraphQL client in HTTP mode, and GHSA-w4q6-qw23-4rg7 (high, July) was a denial of service. The boundaries are the best documented in this batch. OAuth with scopes is the remote default, with per-call scope challenges since v1.11.0 and fine-grained PATs or GitHub App tokens for headless runs, always in the Authorization header. Every remote toolset has a /readonly URL, and --read-only drops write tools even when named. delete_repository makes the user type the repository name through elicitation. delete_file and the rest run without it, and 27 of 35 write tools leave destructiveHint unset. Public issue and comment text is untrusted, and lockdown mode filters it by push access but calls itself best-effort. MCP calls reach the audit log only as ordinary API calls. Four, because read-only is a URL away and injection still arrives through issues. Desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made.</description>
</item>
<item>
<title>Listed: GitHub MCP Server, grade BB (70.5/100)</title>
<link>https://www.anchorterminal.com/tools/github-mcp-server</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/github-mcp-server#run-2026-10-01</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>listing</category>
<description>GitHub&#39;s official MCP server (Go) exposing repositories, issues, pull requests, Actions, code security, discussions, gists, notifications, projects and more as toolsets.</description>
</item>
</channel>
</rss>
