GitHub Actions MCP
Connects AI assistants to GitHub Actions workflows to monitor CI/CD pipelines, view run logs, diagnose failures, and optionally trigger or manage workflows with granular permission controls.
README
github-actions-mcp
A Model Context Protocol (MCP) server for GitHub Actions integration. Give your AI assistant eyes on your CI/CD pipelines.
Status: Alpha (v0.1.0)
Author: Claude + MOD
License: MIT
Organization: ArkTechNWA
Quick Start
# 1. Clone and build
git clone https://github.com/ArkTechNWA/github-actions-mcp.git
cd github-actions-mcp
npm install && npm run build
# 2. Add to Claude Code
claude mcp add --transport stdio github-actions -- \
bash -c "GITHUB_TOKEN=\$(gh auth token) node $(pwd)/build/index.js"
# 3. Restart Claude Code and use
# gha_list_workflows, gha_list_runs, gha_diagnose_failure, etc.
Why?
Your AI assistant can write code, but it's blind to whether it passes CI. It can suggest fixes, but can't see the actual error logs from your failed workflow. It can't trigger a deployment or re-run a flaky test.
github-actions-mcp connects Claude to your GitHub Actions workflows — safely.
Philosophy
- Safety by default — Read-only access to workflows and runs
- User controls exposure — Whitelist repos, permission levels
- Never hang — GitHub API timeouts, circuit breakers
- Structured output — JSON for machines, summaries for AI
- Fallback AI — Haiku for log analysis and failure diagnosis
Features
Perception (Read)
- List workflows in a repository
- Get workflow run history and status
- Stream/fetch run logs
- Check job and step status
- View workflow file definitions
Action (Write)
- Trigger workflow_dispatch events
- Re-run failed jobs
- Cancel running workflows
- Enable/disable workflows
Analysis (Optional AI Fallback)
- "Why did this build fail?" synthesis
- Log pattern analysis
- Flaky test detection
Permission Model
Permission Levels
| Level | Description | Default |
|---|---|---|
read |
List workflows, runs, logs | ON |
trigger |
Dispatch workflows, re-run jobs | OFF |
cancel |
Cancel running workflows | OFF |
admin |
Enable/disable workflows | OFF |
Repository Filtering
{
"permissions": {
"read": true,
"trigger": false,
"cancel": false,
"admin": false,
"whitelist_repos": [
"ArktechNWA/*",
"myorg/myapp"
],
"blacklist_repos": [
"*/infrastructure",
"*/secrets-*"
]
}
}
Rules:
- Blacklist always wins
- Empty whitelist = all accessible repos allowed
- Patterns support
org/*and*/repowildcards
Bypass Mode
github-actions-mcp --bypass-permissions
Full access to all repos you can see. You own the consequences.
Authentication
GitHub Personal Access Token (classic or fine-grained):
# Environment variable
export GITHUB_TOKEN=ghp_xxxxxxxxxxxx
# Or in config
{
"auth": {
"token_env": "GITHUB_TOKEN"
}
}
Required scopes:
repo(for private repos)actions:read(minimum for read-only)actions:write(for trigger/cancel)
Tools
Workflows
gha_list_workflows
List workflows in a repository.
gha_list_workflows({
repo: string, // "owner/repo"
state?: "active" | "disabled" | "all"
})
gha_get_workflow
Get workflow definition and metadata.
gha_get_workflow({
repo: string,
workflow: string | number // workflow file name or ID
})
Runs
gha_list_runs
List workflow runs with filtering.
gha_list_runs({
repo: string,
workflow?: string, // filter by workflow
branch?: string, // filter by branch
status?: "queued" | "in_progress" | "completed",
conclusion?: "success" | "failure" | "cancelled" | "skipped",
limit?: number // default: 10
})
Returns:
{
"runs": [
{
"id": 12345,
"workflow": "CI",
"status": "completed",
"conclusion": "failure",
"branch": "main",
"commit": "abc1234",
"commit_message": "Fix login bug",
"triggered_by": "push",
"started_at": "2025-12-29T10:00:00Z",
"duration": "3m 42s",
"status_icon": "✗"
}
],
"summary": "Last 10 runs: 7 passed, 2 failed, 1 cancelled"
}
gha_get_run
Get detailed run information including jobs.
gha_get_run({
repo: string,
run_id: number,
include_jobs?: boolean // default: true
})
gha_get_run_logs
Fetch logs for a workflow run.
gha_get_run_logs({
repo: string,
run_id: number,
job?: string, // specific job name
step?: string, // specific step name
grep?: string, // filter log lines
tail?: number // last N lines
})
Actions
gha_trigger_workflow
Trigger a workflow_dispatch event. Requires trigger permission.
gha_trigger_workflow({
repo: string,
workflow: string, // workflow file name
ref: string, // branch or tag
inputs?: Record<string, string> // workflow inputs
})
gha_rerun_workflow
Re-run a workflow. Requires trigger permission.
gha_rerun_workflow({
repo: string,
run_id: number,
failed_only?: boolean // only re-run failed jobs
})
gha_cancel_run
Cancel a running workflow. Requires cancel permission.
gha_cancel_run({
repo: string,
run_id: number
})
gha_set_workflow_state
Enable or disable a workflow. Requires admin permission.
gha_set_workflow_state({
repo: string,
workflow: string,
enabled: boolean
})
Analysis
gha_diagnose_failure
AI-powered failure diagnosis. Gathers logs and context.
gha_diagnose_failure({
repo: string,
run_id: number,
use_ai?: boolean // use Haiku for synthesis
})
Returns:
{
"run_id": 12345,
"workflow": "CI",
"conclusion": "failure",
"failed_jobs": ["test"],
"failed_steps": ["Run pytest"],
"error_context": "[... relevant log lines ...]",
"synthesis": {
"analysis": "Test failed due to missing fixture. The 'db' fixture was removed in commit abc123 but test_user.py still depends on it.",
"suggested_fix": "Either restore the db fixture or update test_user.py to use the new database setup",
"confidence": "high"
}
}
NEVERHANG Architecture
GitHub API can be slow. Log downloads can hang. We guarantee responsiveness.
Timeouts
- API calls: 30s default
- Log downloads: 60s default
- Configurable per-operation
Streaming
- Large logs streamed in chunks
- Progress updates for long downloads
- Client can cancel anytime
Circuit Breaker
- 3 failures in 60s → 5 minute cooldown
- Respects GitHub rate limits (5000/hour)
- Backs off on 403/429 responses
Rate Limit Awareness
{
"rate_limit": {
"remaining": 4892,
"reset_at": "2025-12-29T11:00:00Z"
}
}
Fallback AI
Optional Haiku integration for log analysis.
{
"fallback": {
"enabled": true,
"model": "claude-haiku-4-5",
"api_key_env": "GHA_MCP_FALLBACK_KEY",
"max_log_lines": 500,
"max_tokens": 500
}
}
When used:
gha_diagnose_failurewithuse_ai: true- Complex multi-job failures
- Pattern detection in flaky tests
Configuration
Config File
~/.config/github-actions-mcp/config.json:
{
"auth": {
"token_env": "GITHUB_TOKEN"
},
"permissions": {
"read": true,
"trigger": false,
"cancel": false,
"admin": false,
"whitelist_repos": [],
"blacklist_repos": []
},
"neverhang": {
"api_timeout": 30000,
"log_timeout": 60000
},
"fallback": {
"enabled": false
}
}
Claude Code Integration
{
"mcpServers": {
"github-actions": {
"command": "github-actions-mcp",
"env": {
"GITHUB_TOKEN": "your-token-here"
}
}
}
}
Installation
npm install -g @arktechnwa/github-actions-mcp
Requirements
- Node.js 18+
- GitHub Personal Access Token
- Optional: Anthropic API key for fallback AI
Security Considerations
- Token scoping — Use fine-grained PATs with minimal permissions
- Repo filtering — Whitelist only repos you want AI to access
- No secrets exposure — Workflow secrets never exposed in logs
- Audit trail — All actions logged
Credits
Created by Claude in collaboration with Meldrey. Part of the ArktechNWA MCP Toolshed.
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。