跳到主要内容
Supermarket
All guides (mostly Chinese)
Read-only GitHub MCP · English walkthrough

Before a read-only GitHub MCP trial: read the evidence, not just the score

An English walkthrough of an existing public report: verify its date, follow a finding to source, and define a bounded PR-reading trial before connecting an account.

Updated 2026-10-04 6 min read

Who this is for: For developers considering a public MCP repository for one PR-reading task. This walkthrough is in English; the linked report, project lookup, and sign-in screens are currently in Chinese. It is not a translation of every finding or a runtime security assessment.

1

Start with an existing report — no account needed

Open the stored GitHub MCP Server report below. It is a real report in the public catalog, not a new evaluation triggered by this guide. Read its generation time and engine version before interpreting any finding; this guide's update date does not refresh the report or the source repository.

The report reads public project materials using static checks and, where recorded in its methodology, AI review. It does not install or execute the project, connect to your GitHub account, or test a hosted MCP endpoint. A score is not a security certification or permission to connect production data.

Open the existing GitHub MCP report (Chinese; no sign-in)
2

Find the provenance and one decision-relevant finding

  • Look for 评测生成时间(北京时间): the report's generation time, shown in Beijing time (UTC+8). 本报告引擎 is the stored engine version; 当前引擎 is today's engine version. Different versions are not directly comparable, and an older score is not silently recomputed.
  • 安全证据 means security evidence. For one finding, record its file, rule, available location, and the question you need to verify against the original public source. A suspected pattern is not a confirmed exploit or leaked secret; missing location or missing evidence remains a limitation.
  • 采用建议 means adoption advice, and 置信度 means confidence in the available evidence, not the probability that a project is safe. A diagram is inferred from documentation, not an execution trace. Do not use a polished diagram or high total score to override a blocking finding.
  • 方法、证据与局限 contains the recorded method and limitations. If evidence is stale, ambiguous, or inconsistent with current source, pause the adoption decision and verify it; do not submit private files or credentials to fill the gap.
3

Separate the PR task, exposed tools, and account scope

Define one trial: read a specified PR in a test repository you control, list changed files, and produce questions for human review. Do not comment, submit a review, merge, or change repository content. This is a proposed acceptance procedure, not a task Skill Supermarket has executed for you.

GitHub's current server configuration supports selecting tools or toolsets and a read-only mode that removes write tools, including write tools explicitly requested. Check the actual exposed tools for your chosen client and server version. Restrict the underlying GitHub identity separately: filtering tools does not narrow which resources that identity can access.

  • Configure authentication only in your own trusted client, using the smallest resource and permission scope the task needs. Do not paste tokens, private code, customer data, or secret-bearing URLs into this site.
  • Compare the authorized PR's number, title, changed files, and diff with the GitHub web view. For a negative test, use a private test repository you control but have not granted to this identity; a public repository cannot demonstrate that private-resource access is denied.
  • Stop if unnecessary write tools are exposed, private resources outside the intended scope are accessible, output cannot be checked, or a blocking finding remains unresolved. Do not create a real PR comment as a test.
4

Bring your own public project without starting a job

Use the project lookup below with a public GitHub, npm, or PyPI source. It only searches existing catalog entries: it does not fetch the project, create an evaluation, or consume an evaluation credit. A repository match does not prove that a particular branch, commit, or subdirectory was evaluated.

On the Chinese lookup page, 阅读已有报告 · 无需登录 opens an existing report; no match is not a failed evaluation. If you choose to create a new report, the next step requires signing in and the result is public. Opening the workbench is not submission: confirm the canonical source and displayed allowance before starting a job. This guide does not change account verification, quota, or pricing.

5

A useful outcome is a decision you can explain

You should leave with a dated piece of evidence, a question verified against source, a bounded task, and explicit stop conditions. Static evidence can help you reject a candidate or plan a trial; it cannot establish that current runtime behavior, hosted infrastructure, or your credentials are safe.

If the report does not supply enough evidence for that decision, keep the result unresolved rather than treating a missing warning as approval. Read-only access and a successful test also do not replace production authorization, isolation, monitoring, and rollback planning.

Primary sources and verification links

Keep exploring
Put it into practice

Have a public project in mind? Look it up first.

Lookup is anonymous and only reads existing catalog entries. The next screen is in Chinese. Creating a new public report requires sign-in and confirmation; lookup itself starts no job.

Look up a public project (Chinese)