bgauryy

octocode-mcp

VOUCH63·C

Model Context Protocol (MCP) server for advanced GitHub repository analysis and code discovery. Provides AI assistants with powerful tools to search, analyze, and understand codebases across GitHub.

Trust report

Scanned 2026-07-09 · MCP 2025-11-25

Scored by MCP Vouch against the OWASP MCP Top 10. SKIP applies to HTTP-only checks not relevant for stdio servers and is excluded from the score.

Is octocode-mcp safe to use?

octocode-mcp scores 63/100 — grade C, which leaves real gaps worth reading before you connect an agent. It passes 2 of the 7 OWASP MCP Top-10 checks that apply to it, with Insufficient Input Validation, Unauthorized Capability Exposure, Lack of Audit and Telemetry, Inadequate Rate Limiting, and Supply Chain Risk returning a warning rather than a pass. 3 further checks do not apply to this server's transport and are excluded from the score entirely — skipped is not the same as failed. This is what the scanner found on 2026-07-09, not a guarantee. Re-run it yourself with `npx mcpr scan`.

What a grade C means, the ten checks behind it, and the point maths are all on how we score MCP server trust.

Slug

npm-octocode-mcp

License

MIT

Quality score

Not yet probed

Trust score

VOUCH63·C

Latest version

14.1.1

Published

2026-04-18

Homepage

octocode.ai

Repository

git+https://github.com/bgauryy/octocode-mcp.git

Capabilities

Not yet declared in the manifest.

Embed the live badge

Always reflects the current grade. Score drops → badge drops. No vanity lock.

Live MCP Vouch trust badge for npm-octocode-mcp
[![MCP trust score](https://mcp-registry-dh5.pages.dev/api/badge/npm-octocode-mcp.svg)](https://mcp-registry-dh5.pages.dev/servers/npm-octocode-mcp/)

Install

One-click cross-client install (Claude Code, Claude Desktop, Cursor, Windsurf) coming soon. The registry will write the correct config fragment to the correct file — no copy-paste.

Frequently asked questions

Is octocode-mcp safe to use?
octocode-mcp scores 63/100 — grade C, which leaves real gaps worth reading before you connect an agent. It passes 2 of the 7 OWASP MCP Top-10 checks that apply to it, with Insufficient Input Validation, Unauthorized Capability Exposure, Lack of Audit and Telemetry, Inadequate Rate Limiting, and Supply Chain Risk returning a warning rather than a pass. 3 further checks do not apply to this server's transport and are excluded from the score entirely — skipped is not the same as failed. This is what the scanner found on 2026-07-09, not a guarantee. Re-run it yourself with `npx mcpr scan`.
What is the octocode-mcp trust score based on?
Ten checks derived from the OWASP MCP Top 10, run against the live server by the open-source MCP Vouch scanner. Applicable checks are summed and scaled to 0–100; checks that do not apply to the server's transport are skipped and leave the denominator entirely.
How do I install octocode-mcp?
octocode-mcp is installed like any other MCP server — add it to your client's MCP configuration. Cross-client one-click install is coming to MCP Registry; until then, the repository and homepage links on this page carry the maintainer's own instructions.