Git MCP Server (Ray0907/git-mcp-server) is an MCP server listed on the M8ven Trust Index. It scores 72 out of 100, grade C. It declares 23 tools. No publisher has claimed this listing.

C
Caution
72/100

Git MCP Server

A modular MCP server that provides a unified interface for interacting with GitHub and GitLab, including enterprise and self-hosted instances. It enables comprehensive management of repositories, issues, pull requests, and CI/CD pipelines through natural language.

Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

Ray0907

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
⚠️
Known vulnerabilities in dependencies: 2 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 1 credential: GIT_TOKEN
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// tools this server exposes23 tools

These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.

create_issue

Create a new issue in a project

get_issue

Get details of a specific issue in a project

list_issues

List issues in a project with optional filters

update_issue

Update an existing issue in a project

create_pull_request

Create a new pull request (merge request in GitLab)

get_pull_request_diffs

Get the changes/diffs of a pull request to see what files were modified

get_pull_request

Get details of a pull request (merge request in GitLab)

list_pull_requests

List pull requests (merge requests in GitLab) with optional filters

merge_pull_request

Merge a pull request (merge request in GitLab)

create_comment

Add a comment to an issue or pull request

list_comments

List all comments on an issue or pull request

get_job_log

Get the log/trace output of a CI/CD job

get_pipeline

Get details of a specific CI/CD pipeline (workflow run in GitHub)

list_pipeline_jobs

List all jobs in a CI/CD pipeline to see results

list_pipelines

List CI/CD pipelines (workflow runs in GitHub) with optional filters

create_branch

Create a new branch in the repository. Use this before making code changes to work on a separate branch.

get_file_contents

Get the contents of a file or directory from a repository

get_repository_tree

List files and directories in a repository. Use recursive=true to get full tree.

list_branches

List branches in a repository. Optionally search for specific branches.

list_commits

List commits in a repository. Filter by branch, path, date range, or author.

push_files

Push multiple files to a repository in a single commit. Supports create, update, delete, and move actions.

search_code

Search for code in a repository. Returns matching files and lines.

get_me

Get information about the currently authenticated user.

// known CVEs in dependencies2 high

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

high@modelcontextprotocol/sdk@1.24.3GHSA-345p-7cg4-v4c7

@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse

high@modelcontextprotocol/sdk@1.24.3GHSA-8r9q-7v3j-jr4g

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configGIT_API_URL"": "https://github.your-company.com/api/v3",
configGIT_AUTH_COOKIE_PATH
configGIT_AUTH_TYPENo bearer Auth type: bearer or private-token
configGIT_OAUTH_CLIENT_ID
configGIT_OAUTH_TOKEN_PATH
configGIT_PROVIDER"": "github",
configGIT_READ_ONLY"": "true"
🔐 secretGIT_TOKEN"": "ghp_xxxxxxxxxxxxxxxxxxxx"
configGIT_TOOL_FILTER
configGIT_USE_OAUTH
configLOG_LEVELNo info Log level: debug, info, warn, error
configMCP_HOST
configMCP_PORT
configMCP_TRANSPORT
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

23/23 tools missing one or more hints — create_issue (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); get_issue (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); list_issues (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +20 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Production dependencies are patched

0 critical, 2 high severity in production deps — @modelcontextprotocol/sdk@1.24.3 (high), @modelcontextprotocol/sdk@1.24.3 (high)

Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.

Domain consistency

npm scope @raytien doesn't match GitHub owner ray0907

Use the same org name across GitHub, npm, and your homepage so users can verify the publisher.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 4 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/ray0907/git-mcp-server?variant=verified)](https://m8ven.ai/mcp/ray0907/git-mcp-server)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: 8c0ae3af23a8e0eb6ab5a2e279ac87473da3c676
code hash: 0c3b1885b428acdb417cb7a6eb59998506b08f2aca22443c4c7f3657bd482e8d
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client