Describe the feature or problem you’d like to solve
When github-mcp-server is configured with a GitHub App installation token or fine-grained PAT containing write access (contents: write), tools like create_or_update_file and push_files have full authorization to modify any file within the target repository.
In autonomous agent workflows, this creates a significant privilege escalation and supply chain attack surface:
- Workflow Tampering: If an agent encounters indirect prompt injection from untrusted issue bodies, dependencies, or external web search results, it can be manipulated into writing arbitrary code into
.github/workflows/deploy.yml or .github/actions/*.
- Governance Bypass: An agent could alter
CODEOWNERS, security policies, or dependency lockfiles in ways that bypass intended organizational guardrails.
Currently, the server only offers a binary --read-only flag. There is no intermediate guardrail that permits normal application code modifications (e.g., in src/**) while restricting writes to sensitive security and CI/CD paths.
Proposed solution
Add path-scoped write guardrails via a new CLI argument --deny-paths (or an equivalent rule block in governance policy configuration):
github-mcp-server --deny-paths ".github/**,CODEOWNERS,**/*.pem"
How it works:
- When
create_or_update_file or push_files is invoked, the server checks the target file path(s) against the glob patterns defined in --deny-paths.
- If any target file path matches a denied pattern, the server rejects the call with an informative MCP tool execution error (e.g.
Access Denied: Writing to path '.github/workflows/ci.yml' is restricted by server policy) before sending any mutation payload to GitHub API.
- Optional complementary flag:
--allow-paths to strictly whitelist allowable subtrees (e.g., --allow-paths "src/**,docs/**,tests/**").
Example prompts or workflows (for tools/toolsets only)
- Safe Agentic Feature Development: A developer runs Claude Code with
github-mcp-server to implement a new feature. The agent can modify src/api/auth.ts and tests/auth.test.ts, but if it hallucinates or attempts to adjust .github/workflows/build.yml to bypass a linter, the server blocks the edit before it reaches the Git tree.
- Automated Documentation & Benchmark Bots: Autonomous bots can be granted permission to push updated benchmarks or documentation into
docs/** or benchmarks/** with zero risk of tampering with deployment scripts.
- Multi-Agent Sandboxing: Subagents can be provisioned write access to their specific module folder while denying write access to organizational root configuration files.
Additional context
This bridges the gap between full --read-only mode and unrestricted write access, enforcing the principle of least privilege at the tool boundary without requiring complex custom reverse proxies.
Describe the feature or problem you’d like to solve
When
github-mcp-serveris configured with a GitHub App installation token or fine-grained PAT containing write access (contents: write), tools likecreate_or_update_fileandpush_fileshave full authorization to modify any file within the target repository.In autonomous agent workflows, this creates a significant privilege escalation and supply chain attack surface:
.github/workflows/deploy.ymlor.github/actions/*.CODEOWNERS, security policies, or dependency lockfiles in ways that bypass intended organizational guardrails.Currently, the server only offers a binary
--read-onlyflag. There is no intermediate guardrail that permits normal application code modifications (e.g., insrc/**) while restricting writes to sensitive security and CI/CD paths.Proposed solution
Add path-scoped write guardrails via a new CLI argument
--deny-paths(or an equivalent rule block in governance policy configuration):github-mcp-server --deny-paths ".github/**,CODEOWNERS,**/*.pem"How it works:
create_or_update_fileorpush_filesis invoked, the server checks the target file path(s) against the glob patterns defined in--deny-paths.Access Denied: Writing to path '.github/workflows/ci.yml' is restricted by server policy) before sending any mutation payload to GitHub API.--allow-pathsto strictly whitelist allowable subtrees (e.g.,--allow-paths "src/**,docs/**,tests/**").Example prompts or workflows (for tools/toolsets only)
github-mcp-serverto implement a new feature. The agent can modifysrc/api/auth.tsandtests/auth.test.ts, but if it hallucinates or attempts to adjust.github/workflows/build.ymlto bypass a linter, the server blocks the edit before it reaches the Git tree.docs/**orbenchmarks/**with zero risk of tampering with deployment scripts.Additional context
This bridges the gap between full
--read-onlymode and unrestricted write access, enforcing the principle of least privilege at the tool boundary without requiring complex custom reverse proxies.