Monitor GitHub repo health, DORA metrics and CI signals from your AI assistant.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
π‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
GitHub repository health monitoring for AI assistants β works with any language, any repo.
This Model Context Protocol (MCP) server gives AI assistants the ability to analyze health, security, CI/CD status, and delivery metrics of any GitHub repository β directly from your conversations.
get_repo_health
analyze_code_scanning
Note: You need a
.envfile with yourGITHUB_TOKENin the directory where you run Claude Code.
projectpulse)Code scanning alertsDependabot alertsMetadata (enabled by default)claude_desktop_config.json. Add the projectpulse entry inside "mcpServers":In a new Claude Desktop conversation, try asking:
"Check the health score of facebook/react"
Claude should call the get_health_score tool and return an A-F grade with a detailed breakdown.
| Problem | Solution |
|---|---|
| Tools not showing up | Restart Claude Desktop after editing the config file |
| "Rate limit exceeded" errors | Make sure GITHUB_TOKEN is set correctly in the config |
| Dependabot/CodeQL data missing | Your token needs Code scanning alerts and Dependabot alerts permissions |
npx not found | Install Node.js (v18 or later) and make sure npx is in your PATH |
Configure a new MCP server with:
stdionpx-y projectpulse-mcpGITHUB_TOKEN = your GitHub PATget_health_scoreCalculates a 0-100 health score with an A-F grade. Evaluates 5 weighted categories: CI reliability (25%), code freshness (20%), security posture (25%), community activity (15%), and maintenance quality (15%). Returns actionable improvement suggestions for low-scoring categories. On repeated calls for the same repo, includes a trend comparison showing score change since last check. Queries multiple GitHub API endpoints and OpenSSF Scorecard.
Side effect: saves a trend snapshot to local disk (~/.projectpulse/snapshots/).
Inputs: owner, repo
Try asking: "What's the health score of microsoft/vscode?"
get_dora_metricsCalculates proxy DORA metrics from public GitHub data: Deployment Frequency (from releases), Lead Time for Changes (PR created β merged), Change Failure Rate (CI failure percentage), and Mean Time to Recovery (CI failure β next success). Returns null for metrics with insufficient data. Queries multiple GitHub API endpoints (releases, pulls, actions) β heavier API usage than single-endpoint tools.
Inputs: owner, repo, days (optional, 7-90, default 30)
Try asking: "Show me the DORA metrics for vercel/next.js over the last 60 days"
compare_reposCompares health scores side-by-side for 2-5 repositories. Returns each repo's full health breakdown ranked by score. Useful for evaluating alternatives or benchmarking your project against similar ones. API calls are multiplied by the number of repos compared.
Inputs: repos (array of {owner, repo})
Try asking: "Compare the health of expressjs/express, fastify/fastify, and koajs/koa"
get_repo_healthFetches basic repository metadata: stars, forks, open issues count, primary language, license, last push date, default branch, and archive status. Use this for a quick overview β for a computed grade, use get_health_score instead.
Inputs: owner, repo
Try asking: "Give me general info about torvalds/linux"
analyze_dependenciesLists Dependabot security alerts for vulnerable package dependencies (npm, pip, Maven, etc.) grouped by severity (critical, high, medium, low). Optionally filter by a specific severity level. Requires a token with Dependabot alerts permission.
Inputs: owner, repo, severity (optional)
Try asking: "Show me critical dependency vulnerabilities in my-org/my-app"
check_ci_statusReturns the most recent CI/CD workflow runs from GitHub Actions: status (success, failure, in_progress), conclusion, branch, duration, and timestamps. Useful for checking if builds are green before deploying or merging.
Inputs: owner, repo, limit (optional, default 10)
Try asking: "Are the CI builds passing for facebook/react?"
analyze_code_scanningLists CodeQL and other code scanning alerts: rule ID, severity, vulnerability message, affected file and line number, and creation date. Requires a token with Code scanning alerts permission. Can optionally trigger a CodeQL scan and wait for results (requires Advanced Setup, not Default Setup).
Inputs: owner, repo, trigger_scan (optional, default false), poll_timeout_seconds (optional, default 300), poll_interval_seconds (optional, default 15)
Try asking: "Are there any code scanning vulnerabilities in my-org/my-api?"
pingSimple connectivity check. Returns "pong" with your message. Use to verify the MCP server is running.
Inputs: message
Security score now blends Dependabot alerts (60%) with OpenSSF Scorecard checks (40%) for a more complete picture. 12 security-relevant checks are evaluated β repos without a scorecard gracefully fall back to Dependabot-only scoring.
New get_dora_metrics tool calculates proxy DORA metrics from public GitHub data:
| Metric | Source | Unit |
|---|---|---|
| Deployment Frequency | Releases | releases/week |
| Lead Time for Changes | PR created β merged | hours (median) |
| Change Failure Rate | CI workflow conclusions | percentage |
| Mean Time to Recovery | CI failure β next success | hours (median) |
Metrics return null when insufficient data is available β works safely on any repository.
Required to avoid rate limits and access security data (Dependabot, CodeQL alerts).
Option A: Fine-grained PAT (Recommended)
Code scanning alertsDependabot alertsMetadata (default)Option B: Classic Token
Generate with repo + security_events scopes.
Providing the token:
claude_desktop_config.json (see Quick Start).env file:
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/projectpulse-mcp)<a href="https://allmcps.com/mcp/projectpulse-mcp"><img src="https://allmcps.com/api/badge/projectpulse-mcp?style=directory" alt="ProjectPulse MCP on AllMCPs" /></a>