Atlas / MCP servers / asyncfuncai / GitHub Chat

GitHub ChatCAUTION

mcp/asyncfuncai/github-chat

A Model Context Protocol (MCP) for analyzing and querying GitHub repositories using the GitHub Chat API.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
1 1r · 0w · 0d
Transport
—
License
MIT
Stars
90
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) for analyzing and querying GitHub repositories using the GitHub Chat API. Official Site: https://github-chat.com

Installation

# Install with pip
pip install github-chat-mcp

# Or install with the newer uv package manager
uv install github-chat-mcp
  1. Start using it with Claude!

Example prompts:

  • "Use github-chat-mcp to analyze the React repository"
  • "Index the TypeScript repository with github-chat-mcp and ask about its architecture"

GitHub Chat MCP server

[](https://smithery.ai/server/github-chat-mcp)

Setup Instructions

Before anything, ensure you have a GitHub Chat API key. This is required to use the service.

Install uv first.

MacOS/Linux:

curl -LsSf https://astral.sh/uv/install.sh | sh

Windows:

powershell -ExecutionPolicy ByPass -c "irm https://astral.sh/uv/install.ps1 | iex"

Setup with Cursor (Recommended)

In mcp.json:

{
"mcpServers": {
"github-chat": {
"command": "uvx",
"args": [
"github-chat-mcp"
]
}
}
}

With above, no envs required since it's a freemium release.

Setup with Claude Desktop

# claude_desktop_config.json
# Can find location through:
# Hamburger Menu -> File -> Settings -> Developer -> Edit Config
# Must perform: brew install uv
{
"mcpServers": {
"github-chat": {
"command": "uvx",
"args": ["github-chat-mcp"],
"env": {
}
}
}
}

Installing via Smithery

You can install GitHub Chat for Claude Desktop automatically via Smithery:

npx -y @smithery/cli install github-chat-mcp --client claude

Using GitHub Chat with Claude

  1. Index a GitHub repository first:

"Index the GitHub repository at https://github.com/username/repo"

  1. Then ask questions about the repository:

"What is the core tech stack used in this repository?"

Debugging

Run:

npx @mode
Read from source at commit 48ee6a5dd195OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add github-chat-mcp --env GITHUB_API_KEY=${GITHUB_API_KEY} -- uvx github-chat-mcp
claude-desktop
{
  "mcpServers": {
    "github-chat-mcp": {
      "command": "uvx",
      "args": [
        "github-chat-mcp"
      ],
      "env": {
        "GITHUB_API_KEY": "${GITHUB_API_KEY}"
      }
    }
  }
}
03

Exposed tools (1)

1 read · 0 write · 0 destructive.

ToolRiskDescription
index_repositoryreadIndex a GitHub repository to analyze its codebase. This must be done before asking questions about the repository.
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (5)

MEDIUMInventory / provenance · inv.binary · CWE-1104
src/github_chat_mcp/__pycache__/server.cpython-310.pyc
server.cpython-310.pyc
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
src/github_chat_mcp/__pycache__/server.cpython-311.pyc
server.cpython-311.pyc
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
src/github_chat_mcp/__pycache__/server.cpython-312.pyc
server.cpython-312.pyc
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:34
curl -LsSf https://astral.sh/uv/install.sh | sh
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:109
curl -LsSf https://astral.sh/uv/install.sh | sh

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 48ee6a5dd195full audit observations/trust-audit/mcp-server/asyncfuncai__github-chat.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0748ee6a5dd195CAUTIONB89first audit
06

Questions

What is the GitHub Chat MCP server?

A Model Context Protocol (MCP) for analyzing and querying GitHub repositories using the GitHub Chat API.

What tools does GitHub Chat expose?

1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is GitHub Chat safe to connect to an agent?

With care. The audit graded it B (89/100) and found 5 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does GitHub Chat need?

It reads GITHUB_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (48ee6a5dd195), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement