Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

Suggestion: add a recommended security policy / rate limiting guide

未关闭
#2,233 2 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

评估

难度
3/5
预计耗时
1-2 天
新手友好度
55/100
Issue 类型
文档
描述清晰度
基本清楚
活跃度
活跃
技术栈
github

调研方向

首先查看仓库 README 和现有文档,以找到放置安全指南的合适位置。使用建议的 PAT scopes、proxy rate limits 和破坏性操作阻止作为明确要求,确定此次贡献应为 README 部分、示例策略文件,还是两者都包括。对于 GitHub MCP server 用户,清晰记录推荐的控制措施和示例默认值,即表示完成。

由索引模型根据 Issue 内容生成。

描述

Context

The GitHub MCP server exposes 83 tools, including destructive operations like delete_file, write operations like push_files and merge_pull_request, and resource creation like create_repository. There are no built-in rate limits or access controls — every tool is available to the agent at all times.

For agents in production workflows, this can be risky. An agent stuck in a loop can create dozens of repos or issues. A prompt injection can trigger file deletion. There's no way to say "read everything but don't delete" without external tooling.

Suggestion

Would the maintainers be open to adding a recommended security policy or rate limiting guide to the repo? This could be:

  1. A documentation section in the README covering best practices for limiting tool access (e.g. using PATs with minimal scopes, using a proxy for rate limiting)
  2. A sample policy file showing recommended rate limits for write operations and blocks on destructive tools

We maintain Intercept, an open-source MCP enforcement proxy, and have published a ready-made policy template for the GitHub MCP server with suggested defaults (file deletion blocked, writes rate limited at 30/hour, repo creation at 5/hour). Happy to contribute a PR if there's interest.

Use case

Developers connecting the GitHub MCP server to Claude Code, Cursor, or other AI agents who want to limit what the agent can do without restricting the PAT scopes (which are too coarse-grained for per-tool control).

主要语言
Go
星标
33.1k
派生
5k
平均合并
2 天 1 小时
30 天内合并 PR
25

贡献指南

打开贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

github/github-mcp-server 的其他 Issue

查看 github/github-mcp-server 的全部 Issue

相似的 Issue

更多 Go Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。