← Agent Sprawl Radar
AGENT SPRAWL RADAR

github-write-mcp

Agent trust inventory, risk explanation, tools, data access, and drift.

Risk score
49
medium
Owner
Unassigned
Status
unreviewed
Recommended action
Require approval before production use because repository write access, confidential data access, no assigned owner.

Findings

SeverityCodeTitleDescriptionEvidence
mediumTOOL_CODE_REPOCode Repo accessAgent has code repo capability that should be inventoried.github
mediumDATA_CONFIDENTIALCONFIDENTIAL data accessAgent appears to access confidential data.MCP server can write repository content
mediumNO_OWNERNo owner assignedAgent has no accountable owner in the registry..cursor/mcp.json
highTOOL_WRITE_ACCESSWrite, admin, or execute accessAgent can mutate systems, administer resources, or execute operations.github

Tools

NameCategoryActionTarget
githubcode_repowritegithub.com/example/platform

Data access

ClassLocationEvidence
confidentialrepo contentsMCP server can write repository content

Drift history

Raw config

{
  "GITHUB_TOKEN": "[REDACTED]",
  "args": [
    "github-mcp-server"
  ],
  "command": "npx"
}