Skip to content

feat: Support path-scoped mutation guardrails (--deny-paths) to protect .github/workflows and root configs #3344

Description

@UmeshCode1

Describe the feature or problem you’d like to solve

When github-mcp-server is configured with a GitHub App installation token or fine-grained PAT containing write access (contents: write), tools like create_or_update_file and push_files have full authorization to modify any file within the target repository.

In autonomous agent workflows, this creates a significant privilege escalation and supply chain attack surface:

  • Workflow Tampering: If an agent encounters indirect prompt injection from untrusted issue bodies, dependencies, or external web search results, it can be manipulated into writing arbitrary code into .github/workflows/deploy.yml or .github/actions/*.
  • Governance Bypass: An agent could alter CODEOWNERS, security policies, or dependency lockfiles in ways that bypass intended organizational guardrails.

Currently, the server only offers a binary --read-only flag. There is no intermediate guardrail that permits normal application code modifications (e.g., in src/**) while restricting writes to sensitive security and CI/CD paths.

Proposed solution

Add path-scoped write guardrails via a new CLI argument --deny-paths (or an equivalent rule block in governance policy configuration):

github-mcp-server --deny-paths ".github/**,CODEOWNERS,**/*.pem"

How it works:

  1. When create_or_update_file or push_files is invoked, the server checks the target file path(s) against the glob patterns defined in --deny-paths.
  2. If any target file path matches a denied pattern, the server rejects the call with an informative MCP tool execution error (e.g. Access Denied: Writing to path '.github/workflows/ci.yml' is restricted by server policy) before sending any mutation payload to GitHub API.
  3. Optional complementary flag: --allow-paths to strictly whitelist allowable subtrees (e.g., --allow-paths "src/**,docs/**,tests/**").

Example prompts or workflows (for tools/toolsets only)

  1. Safe Agentic Feature Development: A developer runs Claude Code with github-mcp-server to implement a new feature. The agent can modify src/api/auth.ts and tests/auth.test.ts, but if it hallucinates or attempts to adjust .github/workflows/build.yml to bypass a linter, the server blocks the edit before it reaches the Git tree.
  2. Automated Documentation & Benchmark Bots: Autonomous bots can be granted permission to push updated benchmarks or documentation into docs/** or benchmarks/** with zero risk of tampering with deployment scripts.
  3. Multi-Agent Sandboxing: Subagents can be provisioned write access to their specific module folder while denying write access to organizational root configuration files.

Additional context

This bridges the gap between full --read-only mode and unrestricted write access, enforcing the principle of least privilege at the tool boundary without requiring complex custom reverse proxies.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions