64
/ 100
12 hours ago
glama

okffs

An MCP server that lets Claude Code manage GitHub issues, branches, and pull requests through natural language, automating the full development workflow from planning to closing.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
⚠️
Known vulnerabilities in dependencies: 3 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 1 credential: GITHUB_TOKEN
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies3 high

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

high@modelcontextprotocol/sdk@1.12.0GHSA-345p-7cg4-v4c7

@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse

high@modelcontextprotocol/sdk@1.12.0GHSA-8r9q-7v3j-jr4g

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

high@modelcontextprotocol/sdk@1.12.0GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configGITHUB_OWNER1. / GITHUB_REPO in .env.
configGITHUB_REPO1. GITHUB_OWNER / in .env.
🔐 secretGITHUB_TOKENghp_your_token_here
configOKFFS_AUTOPILOT
configOKFFS_AUTO_MERGE_BASEfalse Let merge_pull_request autonomously merge a green, threads-resolved issue PR into the base branch. Never merges OKFFS_PROTECTED_BRANCH.
configOKFFS_AUTO_PRfalse Open a draft PR when a new issue branch is created.
configOKFFS_BASE_BRANCHrepo default Branch new issue branches are created from.
configOKFFS_CLASSIC_PATfalse Set true only with a classic admin:org PAT — enables org-level Issue Field Priority/Effort (broad token; security tradeoff).
configOKFFS_DEFAULT_ASSIGNEESComma-separated usernames assigned to every new issue.
configOKFFS_DEFAULT_EFFORTOKFFS_DEFAULT_PRIORITY / — Board Priority/Effort fallback when none is inferred or given.
configOKFFS_DEFAULT_LABELSComma-separated labels merged with inferred ones.
configOKFFS_DEFAULT_PRIORITY/ OKFFS_DEFAULT_EFFORT — Board Priority/Effort fallback when none is inferred or given.
configOKFFS_DEFAULT_TYPENative Issue Type fallback when none is inferred or given (e.g. Task).
configOKFFS_EXCLUDE_DOCSCLAUDE.md, CONTRIBUTING.md, and README.md are intentionally left for you to maintain. Exclude specific files per repo with (valid: CHANGELOG.md, SECURITY.md).
configOKFFS_IDENTIFIERPrefix for branch names: {number}-{identifier}-{slug}.
configOKFFS_INFER_EFFORTOKFFS_INFER_PRIORITY / true Let Claude infer priority/effort from the task.
configOKFFS_INFER_PRIORITY/ OKFFS_INFER_EFFORT true Let Claude infer priority/effort from the task.
configOKFFS_INFER_TYPEtrue Let Claude infer the native GitHub Issue Type (Task/Bug/Feature/…) from the task. Org-level; skipped cleanly on user repos.
configOKFFS_PROJECT_AUTO_ADDAuto-add () is a fallback for boards without GitHub's native "Auto-add to project" workflow — leave it false if your board already auto-adds.
configOKFFS_PROJECT_ENABLEDupdate_project_status Moves an issue between board columns (Backlog, Ready, In Progress, Review). Needs .
configOKFFS_PROJECT_IDPVT_kwHO... # the board's GraphQL node ID
configOKFFS_PROJECT_INITIAL_STATUSColumn a freshly added issue lands in (e.g. Backlog).
configOKFFS_PROMOTION_AUTO_REVIEWOKFFS_PROMOTION_REVIEWERS — Comma-separated reviewers to request on the gate PR (e.g. copilot-pull-request-reviewer[bot]). Only acted on when =true.
configOKFFS_PROMOTION_REVIEWERSComma-separated reviewers to request on the gate PR (e.g. copilot-pull-request-reviewer[bot]). Only acted on when OKFFS_PROMOTION_AUTO_REVIEW=true.
configOKFFS_PROMOTION_STATUSBoard Status column the promotion PR card lands in (e.g. Review). Needs OKFFS_PROJECT_ENABLED.
configOKFFS_PROMPT_METADATAtrue Set false to hide the assignees/labels tip.
configOKFFS_PROTECTED_BRANCHOKFFS_AUTO_MERGE_BASE false Let merge_pull_request autonomously merge a green, threads-resolved issue PR into the base branch. Never merges .
configOKFFS_RESOLVE_THREADSresolve_review_thread Resolves a review thread — only when =true.
configOKFFS_UPDATE_DOCSWith =true, create_pull_request writes doc updates onto the branch so they land in the PR diff:
configOKFFS_UPDATE_GUIDANCEfalse Nudge Claude to keep CLAUDE.md in sync at PR time.
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 1 concrete improvement we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/neturely-okffs-g7jpc6)](https://m8ven.ai/mcp/neturely-okffs-g7jpc6)
commit: 45be5859768e88a3172da5ba8b17e2da05651e3f
code hash: 756672b8c43e704e651298f9b3e38fdda592b3d3bed9e89921a0aa79de312ff6
verified: 7/31/2026, 9:04:38 AM
view raw JSON →
okffs · M8ven Trust Score | M8ven