Atlas / MCP servers / wham / GitHub Brain

GitHub BrainBLOCK

mcp/wham/github-brain

An experimental GitHub MCP server with local database.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
5 3r · 2w · 0d
Transport
—
License
MIT
Stars
78
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

GitHub Brain MCP Server

GitHub Brain is an experimental MCP server for summarizing GitHub discussions, issues, and pull requests. Answer questions like:

  • What are the contributions of user X in the last month?
  • Summarize this month's discussions.

https://github.com/user-attachments/assets/80910025-9d58-4367-af00-bf4c51e6ce86

GitHub Brain complements (but does not replace) the official GitHub MCP server. It stores GitHub data in a local database for:

  • Fast responses
  • More than the standard 100-item API limit
  • Token-efficient Markdown output

GitHub Brain is programmed in Markdown.

Installation

npm i -g github-brain

Rerun to update. sudo may be required on some systems.

Alternatively use npx to run without installing globally and needing sudo.

npx github-brain@latest

Usage

github-brain

Or with npx:

npx github-brain@latest

Launches the interactive TUI where you can:

  1. Setup - Configure authentication and settings
  2. Login with GitHub (OAuth) - Recommended for most users
  3. Login with Personal Access Token - For fine-grained tokens or when OAuth is unavailable
  4. Open configuration file - Edit .env directly
  5. Pull - Populate the local database with GitHub data

Re-run pull anytime to update the database with new GitHub data.

The app loads environment variables from a .env file in the GitHub Brain's home directory - ~/.github-brain by default.

Example .env file

GITHUBTOKEN=yourgithub_token ORGANIZATION=my-org

Read from source at commit 8ee094da006fOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add github-brain -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "github-brain": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (5)

3 read · 2 write · 0 destructive.

ToolRiskDescription
AdvancedwriteEdit configuration file
BackreadEsc
ExitreadCtrl+C
PullwriteSync GitHub data to local database
SetupreadConfigure GitHub username and organization
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (1 observation(s))
Shell
declared (3 observation(s))
Dependencies
pinned
Secrets in source
none-found

Findings (2)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
main.go:579
func (d *DB) Exec(query string, args ...interface{}) (sql.Result, error) {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:54
- Open configuration file - Edit `.env` directly
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 8ee094da006ffull audit observations/trust-audit/mcp-server/wham__github-brain.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-078ee094da006fBLOCKD69first audit
06

Questions

What is the GitHub Brain MCP server?

An experimental GitHub MCP server with local database.

What tools does GitHub Brain expose?

5 in total: 3 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is GitHub Brain safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does GitHub Brain need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (8ee094da006f), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement