MCP server intelligence profile

Microsoft GitHub Advisory MCP Server

Enables querying GitHub Security Advisories from a local cloned advisory database using tools like list_advisories and get_advisory

Local OnlyOfficial distributionmicrosoft
Verified cleanSource Git · cd68016c7ea18e4e7121dee0ffeee30131a2e988

Our scanner tested version cd68016c7ea18e4e7121dee0ffeee30131a2e988 without proving a finding in the methods exercised. This is not a guarantee that every deployment is secure.

1Distribution channel
2Independently observed tools
0Linked remote endpoints
AvailableVersion intelligence

Install and connect

Installation and connection instructions are shown only when supported by retained package, repository, or endpoint evidence.

No verified installation or connection method is available in the retained evidence yet.

Identity

Canonical slugmicrosoft-github-advisory-mcp-server-a7df2f22DeploymentLocal Only
Canonical packageRepositorymicrosoft/github-advisory-mcp
First publishedLatest release
Last security verificationAug 25, 2026Classification confidence90%
PublicationPublishedOfficial distributionYes

Distributions

ChannelIdentifierCurrent versionVersionsSource
source_gitmicrosoft/github-advisory-mcpcd68016c7ea18e4e7121dee0ffeee30131a2e9881Repository

Current release

PackageVersionPublished / observedInventorySecurity scan
source_gitmicrosoft/github-advisory-mcpcd68016c7ea18e4e7121dee0ffeee30131a2e988CurrentAug 25, 20262 toolsSucceeded · 0 resources · 0 promptsVerified clean
Enterprise protection

Continuously monitor this MCP for security risk

Independently scan the exact version your agents use, receive alerts when its risk changes, and investigate every finding with retained version evidence.

  • Independent exact-version security scans
  • Continuous release and vulnerability monitoring
  • Risk-change alerts with capability context
  • Historical evidence and API exports
Custom pricingContact salesTailored to your organization, integrations, data needs, and support requirements.

Current version evidence

Provenanceimmutable_git_commitSignature
MCP SDKArtifact SHA-256288489e5dc8c0659aaba1efb93cc2a618eb1463e867fe5f62c22a67430efb265
Scannermcp-proof-engine 0.1.0Scan completedAug 25, 2026
Security ratingMethodology
0Proven
473Clean
0Inconclusive
0Flaky
0Errors

Current protocol inventory

2025-06-18Negotiated protocol
github-advisory-serverServer-reported name
1Capability groups
Aug 25, 2026Observed

Tools 2

ToolCategoryAnnotationsRisk
get_advisoryGet detailed information about a specific GitHub security advisory by its GHSA identifier. Returns comprehensive details including description, vulnerabilities, CVSS scores, CWE classifications, and references.
Input schema
{
  "type": "object",
  "properties": {
    "ghsa_id": {
      "type": "string",
      "description": "GHSA identifier (e.g., GHSA-xxxx-xxxx-xxxx)"
    }
  },
  "required": [
    "ghsa_id"
  ]
}
list_advisoriesList GitHub security advisories from local database with optional filters. Returns summary information about advisories including GHSA ID, CVE ID, severity, affected packages, and more.
Input schema
{
  "type": "object",
  "properties": {
    "ghsa_id": {
      "type": "string",
      "description": "GHSA identifier"
    },
    "cve_id": {
      "type": "string",
      "description": "CVE identifier"
    },
    "ecosystem": {
      "type": "string",
      "enum": [
        "rubygems",
        "npm",
        "pip",
        "maven",
        "nuget",
        "composer",
        "go",
        "rust",
        "erlang",
        "actions",
        "pub",
        "other",
        "swift"
      ],
      "description": "Package ecosystem"
    },
    "severity": {
      "type": "string",
      "enum": [
        "low",
        "medium",
        "high",
        "critical",
        "unknown"
      ],
      "description": "Severity level"
    },
    "cwes": {
      "type": "string",
      "description": "Comma-separated CWE identifiers (e.g., '79,284,22')"
    },
    "is_withdrawn": {
      "type": "boolean",
      "description": "Filter withdrawn advisories"
    },
    "affects": {
      "type": "string",
      "description": "Package name filter"
    },
    "published": {
      "type": "string",
      "description": "Published date or range"
    },
    "updated": {
      "type": "string",
      "description": "Updated date or range"
    },
    "per_page": {
      "type": "number",
      "minimum": 1,
      "maximum": 100,
      "description": "Results per page (max 100)"
    },
    "direction": {
      "type": "string",
      "enum": [
        "asc",
        "desc"
      ],
      "description": "Sort direction"
    },
    "sort": {
      "type": "string",
      "enum": [
        "updated",
        "published"
      ],
      "description": "Sort field"
    }
  }
}

Resources 0

  • None observed.

Resource templates 0

  • None observed.

Prompts 0

  • None observed.

Remote endpoints

EndpointTransportAuthenticationHealthObserved
No verified remote endpoint is linked.

Microsoft GitHub Advisory MCP Server questions

How do I install Microsoft GitHub Advisory MCP Server?

No verified package installation command is available in the retained catalog evidence.

What tools does Microsoft GitHub Advisory MCP Server provide?

Microsoft GitHub Advisory MCP Server exposed 2 tools during independent protocol observation, including get_advisory, list_advisories.

Is Microsoft GitHub Advisory MCP Server secure?

Our scanner tested version cd68016c7ea18e4e7121dee0ffeee30131a2e988 without proving a finding in the methods exercised. This is not a guarantee that every deployment is secure.

Company and product intelligence

These internal links are derived from strong identity fields such as the implementation name, package, repository, vendor, and listing name—not generic description prose.

Associated company landscape

Microsoft & Azure intelligence →

Association is based on retained identity fields; it does not by itself prove first-party publication.

Explore related MCP server guides

Curated product and capability guides containing this catalog record.

GitHub MCP ServersDatabase MCP ServersOfficial vs Community MCP ServersMCP Servers With Completed Verification

Related MCP servers from this publisher

Related records share independently retained publisher or namespace evidence. They are not automatically endorsed alternatives.

Let’s talk about MCP security.

Share your details and our security team will contact you.