A single static Go binary that speaks the Model Context Protocol
and exposes 18 tools for working with GitHub: repositories, branches,
commits, file contents, issues, pull requests, and search.
No Python, no uv, no runtime dependency to install โ just a binary and
an .mcp.json.
โจ Why this exists
An agent that can only talk about your GitHub repos isn't that useful.
This gives it hands: it can read and write files in a repo, open and
triage issues, push a branch and open a PR, and merge it โ all against
the real GitHub API, with the same guardrails (size caps, friendly
errors, destructive-action annotations) as the sibling connectors.
| Tool | What it does | Write? |
|---|
github_whoami | Get the user authenticated by GITHUB_TOKEN | |
github_list_repos | List repos for a user/org, or the authenticated user | |
github_get_repo | Get one repository's details | |
github_create_repo | Create a new repository | โ๏ธ |
github_list_branches | List branches in a repository | |
github_list_commits | List commits, optionally filtered by branch/path | |
github_get_file_contents | Read a file's content, or list a directory | |
github_create_or_update_file | Create/update a file via a commit (โค 5 MB) | โ๏ธ |
github_list_issues | List issues in a repository | |
github_get_issue | Get one issue's full details | |
github_create_issue | Create a new issue | โ๏ธ |
github_update_issue | Update an issue's title/body/state/labels | โ๏ธ |
github_add_issue_comment | Comment on an issue or PR | โ๏ธ |
github_list_pull_requests | List pull requests | |
github_get_pull_request | Get one PR's full details, incl. diff stats | |
github_create_pull_request | Open a pull request | โ๏ธ |
github_merge_pull_request | Merge a pull request | ๐๏ธ destructive |
github_search_repositories | Search repositories with GitHub search qualifiers | |
Every tool accepts an optional response_format: markdown (default,
pretty tables for a chat UI) or json (for programmatic use).
๐ Quickstart
Fastest path: grab a prebuilt bundle from the latest release โ
download github-mcp-connector-plugin-<version>-<os>-<arch>.zip, unzip it,
and point Cowork/Claude at the plugin/ folder inside (see step 4 of
SETUP.md). No Go toolchain required.
From source:
cd go-server
go mod tidy
go build -o github-connector-server .
cp github-connector-server ../plugin/servers/go/
export GITHUB_TOKEN=ghp_...
./go-server/github-connector-server
Or make build โ see the Makefile for every shortcut
(test, vet, fmt, lint, tidy).
Full walkthrough โ including wiring this up as a Claude/Cowork plugin โ is
in SETUP.md.
๐ Configuration
Everything is environment variables, passed through by the plugin's
.mcp.json:
| Variable | Purpose | Default |
|---|
GITHUB_TOKEN | Personal access token (classic or fine-grained). Needs repo/public_repo and read:org scopes depending on what you use it for. | โ (required) |
GITHUB_API_URL | GitHub Enterprise Server API base URL, e.g. https://github.example.com/api/v3. | (unset โ github.com) |
๐งช Quality bar
This isn't a toy script โ it's got the same checks you'd expect from a
production Go service:
- โ
Unit tests for every input-validation path (
go test ./...)
- โ
go vet + gofmt clean
- โ
golangci-lint (govet, staticcheck, errcheck, gosec, and more)
- โ
govulncheck โ no known vulnerabilities in the dependency graph
- โ
CodeQL static security analysis on every push
- โ
End-to-end verified โ every tool (repos, branches, commits, file
read/write, issues, comments, PRs, merge, search) was exercised against
a real, dedicated GitHub sandbox repo, not mocks
- โ
Dependabot keeps Go modules and Actions current
All of it runs in CI on every push and PR.
๐ท๏ธ Releases & versioning
Versions follow semver and are cut automatically by
release-please from
Conventional Commits on main:
fix: ... โ patch (v0.1.0 โ v0.1.1)
feat: ... โ minor (v0.1.1 โ v0.2.0)
feat!: ... / BREAKING CHANGE: footer โ major (v0.2.0 โ v1.0.0)
Every merged PR updates a standing "chore(main): release vX.Y.Z" PR
with an auto-generated CHANGELOG.md. Merging that PR:
- tags the release and publishes it on GitHub
- builds and attaches zipped, ready-to-install plugin bundles for
linux/darwin/windows ร amd64/arm64
- regenerates
server.json from those exact assets (fresh version +
SHA-256 hashes) and publishes it to the
official MCP Registry via
mcp-publisher, authenticated with GitHub OIDC โ no stored secrets
See .github/workflows/release-please.yml
and .github/workflows/publish-mcp-registry.yml
(also runnable by hand for an existing tag via workflow_dispatch).
๐ Layout
github-mcp-connector/
โโโ README.md โ you are here
โโโ SETUP.md โ step-by-step setup guide
โโโ CONTRIBUTING.md โ how to contribute
โโโ CODE_OF_CONDUCT.md
โโโ SECURITY.md โ vulnerability reporting
โโโ CODEOWNERS
โโโ LICENSE โ MIT
โโโ Makefile โ build / test / lint shortcuts
โโโ .golangci.yml โ lint rules
โโโ release-please-config.json โ semver/changelog automation config
โโโ .release-please-manifest.json
โโโ server.json โ MCP Registry manifest (regenerated fresh per release by CI)
โโโ scripts/
โ โโโ render-server-json.sh โ rebuilds server.json from a release's zip assets
โโโ .github/
โ โโโ workflows/
โ โ โโโ ci.yml โ build, vet, test, lint, govulncheck
โ โ โโโ codeql.yml โ security scanning
โ โ โโโ pr-title.yml โ Conventional Commits PR title check
โ โ โโโ release-please.yml โ version PRs, tagging, GitHub releases
โ โ โโโ publish-mcp-registry.yml โ publishes server.json to the MCP Registry
โ โ โโโ rebuild-release-assets.yml โ manual re-attach fallback
โ โโโ ISSUE_TEMPLATE/
โ โโโ PULL_REQUEST_TEMPLATE.md
โ โโโ dependabot.yml
โโโ go-server/ โ the MCP server source
โ โโโ main.go
โ โโโ main_test.go
โ โโโ go.mod / go.sum
โ โโโ README.md
โโโ plugin/ โ installable Cowork/Claude plugin
โโโ .claude-plugin/plugin.json
โโโ .mcp.json โ holds credentials locally โ never commit real ones
โโโ servers/go/ โ compiled binary goes here
๐ค Contributing
PRs and issues are very welcome โ see CONTRIBUTING.md
for the full guide (setup, coding conventions, how to add a new tool) and
the Code of Conduct.
main is protected: every change, including the maintainer's, lands via
pull request with CI green. PR titles must follow
Conventional Commits โ that's what
drives the automatic versioning above.
Found a security issue? Please follow SECURITY.md
instead of opening a public issue.
๐ License
MIT ยฉ FerhatDundar