An MCP server that lets Claude Code manage GitHub issues, branches, and pull requests through natural language, automating the full development workflow from planning to closing.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
process.env. You'll be asked to provide them before it can run.GITHUB_OWNER— 1. / GITHUB_REPO in .env.GITHUB_REPO— 1. GITHUB_OWNER / in .env.GITHUB_TOKEN— ghp_your_token_hereOKFFS_AUTOPILOTOKFFS_AUTO_MERGE_BASE— false Let merge_pull_request autonomously merge a green, threads-resolved issue PR into the base branch. Never merges OKFFS_PROTECTED_BRANCH.OKFFS_AUTO_PR— false Open a draft PR when a new issue branch is created.OKFFS_BASE_BRANCH— repo default Branch new issue branches are created from.OKFFS_CLASSIC_PAT— false Set true only with a classic admin:org PAT — enables org-level Issue Field Priority/Effort (broad token; security tradeoff).OKFFS_DEFAULT_ASSIGNEES— Comma-separated usernames assigned to every new issue.OKFFS_DEFAULT_EFFORT— OKFFS_DEFAULT_PRIORITY / — Board Priority/Effort fallback when none is inferred or given.OKFFS_DEFAULT_LABELS— Comma-separated labels merged with inferred ones.OKFFS_DEFAULT_PRIORITY— / OKFFS_DEFAULT_EFFORT — Board Priority/Effort fallback when none is inferred or given.OKFFS_DEFAULT_TYPE— Native Issue Type fallback when none is inferred or given (e.g. Task).OKFFS_EXCLUDE_DOCS— CLAUDE.md, CONTRIBUTING.md, and README.md are intentionally left for you to maintain. Exclude specific files per repo with (valid: CHANGELOG.md, SECURITY.md).OKFFS_IDENTIFIER— Prefix for branch names: {number}-{identifier}-{slug}.OKFFS_INFER_EFFORT— OKFFS_INFER_PRIORITY / true Let Claude infer priority/effort from the task.OKFFS_INFER_PRIORITY— / OKFFS_INFER_EFFORT true Let Claude infer priority/effort from the task.OKFFS_INFER_TYPE— true Let Claude infer the native GitHub Issue Type (Task/Bug/Feature/…) from the task. Org-level; skipped cleanly on user repos.OKFFS_PROJECT_AUTO_ADD— Auto-add () is a fallback for boards without GitHub's native "Auto-add to project" workflow — leave it false if your board already auto-adds.OKFFS_PROJECT_ENABLED— update_project_status Moves an issue between board columns (Backlog, Ready, In Progress, Review). Needs .OKFFS_PROJECT_ID— PVT_kwHO... # the board's GraphQL node IDOKFFS_PROJECT_INITIAL_STATUS— Column a freshly added issue lands in (e.g. Backlog).OKFFS_PROMOTION_AUTO_REVIEW— OKFFS_PROMOTION_REVIEWERS — Comma-separated reviewers to request on the gate PR (e.g. copilot-pull-request-reviewer[bot]). Only acted on when =true.OKFFS_PROMOTION_REVIEWERS— Comma-separated reviewers to request on the gate PR (e.g. copilot-pull-request-reviewer[bot]). Only acted on when OKFFS_PROMOTION_AUTO_REVIEW=true.OKFFS_PROMOTION_STATUS— Board Status column the promotion PR card lands in (e.g. Review). Needs OKFFS_PROJECT_ENABLED.OKFFS_PROMPT_METADATA— true Set false to hide the assignees/labels tip.OKFFS_PROTECTED_BRANCH— OKFFS_AUTO_MERGE_BASE false Let merge_pull_request autonomously merge a green, threads-resolved issue PR into the base branch. Never merges .OKFFS_RESOLVE_THREADS— resolve_review_thread Resolves a review thread — only when =true.OKFFS_UPDATE_DOCS— With =true, create_pull_request writes doc updates onto the branch so they land in the PR diff:OKFFS_UPDATE_GUIDANCE— false Nudge Claude to keep CLAUDE.md in sync at PR time.[](https://m8ven.ai/mcp/neturely-okffs-g7jpc6)