5
/ 100
26 days ago
pulsemcp

Octocode

Integrates with GitHub CLI and npm to provide repository analysis, code discovery, file exploration, commit history tracking, and package metadata retrieval with intelligent caching and cross-tool workflow support.

bgauryy/octocode-mcp· npm: octocode-mcp· 88K installs· listed on pulsemcp
Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Hardcoded credentials detected
2 live-looking API keys in source: 1 OpenAI API key, 1 GitHub PAT (classic)
🔐
You'll be asked for 3 credentials: GITHUB_PERSONAL_ACCESS_TOKEN, GITHUB_TOKEN, GEMINI_API_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configALLOWED_PATHSlocal.allowedPaths [] Both Extra path allowlist for local access; empty means home directory only after validation.
configAST_GREP_BIN
configCDP_OUTPUT_DIR
configCDP_SESSION_META_DIR
configDISABLE_TOOLSTOOLS_TO_RUN / ENABLE_TOOLS / tools. unset MCP Whitelist, add to, or remove from the registered tool set. The CLI exposes every tool.
configENABLE_CLONEghCloneRepo Clone a repo or sparse subtree into the local cache for local/LSP analysis. Opt-in (=true). sparsePath
configENABLE_LOCALlocal.enabled true Both Turns local filesystem + LSP tools on/off; set false to disable.
configENABLE_TOOLSTOOLS_TO_RUN / / DISABLE_TOOLS tools. unset MCP Whitelist, add to, or remove from the registered tool set. The CLI exposes every tool.
configGITHUB_API_URLgithub.apiUrl https://api.github.com Both API endpoint; use /api/v3 for GitHub Enterprise.
🔐 secretGITHUB_PERSONAL_ACCESS_TOKEN
🔐 secretGITHUB_TOKENOCTOCODE_TOKEN / GH_TOKEN / env only unset Both GitHub token, in priority order. Tokens stay in env, never in .octocoderc.
configMAX_RETRIESnetwork.maxRetries 3 Both Retry attempts (clamped 0..10).
configNO_COLOR
configOCTOCODE_BASH_LS_BIN
configOCTOCODE_BIN
configOCTOCODE_LSP_CONFIG
configOCTOCODE_NO_STALE_BUILD_WARNING
configOCTOCODE_OUTPUT_DEFAULT_CHAR_LENGTH
configOCTOCODE_OUTPUT_FORMAToutput.format yaml Both Response format: yaml or json.
configPROGRAMFILES
configPROGRAMFILES(X86)
configREQUEST_TIMEOUTnetwork.timeout 30000 Both Request timeout in ms (clamped 5000..300000).
configSystemRoot
configTOOLS_TO_RUN/ ENABLE_TOOLS / DISABLE_TOOLS tools. unset MCP Whitelist, add to, or remove from the registered tool set. The CLI exposes every tool.
configWINDIR
configWORKSPACE_ROOTlocal.workspaceRoot cwd Both Absolute root for resolving relative local paths.
configXDG_CONFIG_HOMELinux ${:-~/.config}/.octocode
🔐 secretGEMINI_API_KEY
configOCTOCODE_AWARENESS_COMPACT
configOCTOCODE_AWARENESS_FAKE_EMBEDDER
configOCTOCODE_EMBED_MODEL
configOCTOCODE_ALLOW_HARNESS_APPLY
configOCTOCODE_HARNESS_BRANCH_OK
configOCTOCODE_MEMORY_HOME
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 2 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/octocode-mcp-kfqg7t)](https://m8ven.ai/mcp/octocode-mcp-kfqg7t)
commit: 7d51c1c865deafc6a574269e578f2f399f9bb0fb
code hash: 6ba8ccf6a1b77ca71037743809ec6f3bda00310a439b3502dc5017a630157f6e
verified: 7/5/2026, 9:11:41 AM
view raw JSON →