Microsoft Copilot security directory

GitHub

Published by Microsoft

High risk

GitHub is a web-based Git repository hosting service. It offers all of the distributed revision control and source code management (SCM) functionality of Git as well as adding its own features.

Security assessment

Plutonium assessed this connector for permissions, capabilities, and security-relevant behavior.

  • Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
  • Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.
  • Can permanently delete data: This connector can erase records, files, or accounts. Once deleted the data may be unrecoverable - even an accidental request can cause permanent loss.
  • Sends your data to outside companies: Anything you share with this connector flows to a third-party service. That company sees, stores, and may use the data according to their own policies.

Available capabilities

This add-on exposes 37 tools or capabilities.

  • Add selected repository to an organization secret (Preview)
  • Check if a user is a repository collaborator
  • Compare two commits (Preview)
  • Create a pull request (Preview)
  • Create a reference (Preview)
  • Create a repository dispatch event (Preview)
  • Create a repository using a template (Preview)
  • Create an issue
  • Create or update a repository secret (Preview)
  • Deletes a GitHub Webhook (Preview)
  • Find issues by state and keyword
  • Get a particular issue of a repository
  • Get a pull request (Preview)
  • Get a reference (Preview)
  • Get a repository by Id (Preview)
  • Get a repository public key (Preview)
  • Get all issues of a repository
  • Get all Pull Requests of A Repository
  • Get the authenticated user
  • Get the list of files from a pull request (Preview)
  • Github MCP Server
  • List repository collaborators
  • Lists all labels for a repository
  • Lists all labels for an issue

The interactive security report will load automatically.