Self-hosting GitHub autonomy engine. MCP server for repository management, CVE scanning, security automation, and GitHub operations.
The server defines 27 tools with explicit schemas and descriptions. Most tools follow verb_noun naming (e.g., fabric_cve_scan, git_steer_repo_list) and have basic parameter schemas. However, there are significant gaps: (1) Many parameter descriptions are missing or generic. For example, fabric_cve_scan's 'repos' parameter has a description, but many tools like fabric_git_get_file lack detailed descriptions for every parameter ('ref' is underdescribed). (2) Output schemas are not documented, the code shows input schemas but no documentation of what each tool returns, which violates the pattern:tool requirement. (3) Error handling is absent from tool descriptions, no guidance on what to do when a CVE lookup fails or a repo is not found. (4) Some tools expose infrastructure concerns that should be abstracted: fabric_cve_queue and fabric_cve_stats reference internal state file 'state/cve-queue.jsonl', leaking implementation details. (5) The fabric_* tools are described as '[git-fabric]' prefixed, which is metadata noise in descriptions; the description should explain what the tool does for the user. Parameter validation rules and constraints (e.g., days_stale range, limit max value) are not consistently documented in descriptions. By baseline, average tool description is 194 chars and avg params per tool is 4; this server's descriptions average ~140 chars and are functional but sparse. Most tools lack the 'actionable context' pattern (when to use this vs. similar tools).
[git-fabric] Compact the CVE queue by removing resolved entries older than the retention period.
[git-fabric] Fetch enriched vulnerability details for a CVE from NVD. Returns severity, CVSS, NVD status, CWE, and references.
[git-fabric] List CVE queue entries filtered by status and severity.
[git-fabric] Scan managed repos for vulnerable dependencies via GitHub Advisory Database. Queues findings to state/cve-queue.jsonl.
[git-fabric] CVE queue health dashboard: totals by status/severity, oldest pending, top repos.
[git-fabric] Commit one or more files to a branch via the GitHub Git Data API.
Output schemas not documented. Code shows input schemas but no definition of what each tool returns. This violates pattern:tool, LLMs need to know the response structure to plan downstream calls and extract data correctly.
Error handling guidance missing. Tool descriptions do not explain what to do when operations fail (e.g., 'CVE not found in NVD', 'repo does not exist'). Agents have no recovery path.
Parameter descriptions sparse or missing validation rules. Example: 'days_stale' in git_steer_branch_reap has no documented range. 'limit' in fabric_cve_queue defaults to 50 but no max is stated. LLMs may pass invalid values.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 61 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 0 | - | v1 |
[git-fabric] Compare two refs to see divergence and changed files.
[git-fabric] Create a new branch from an existing branch.
[git-fabric] Open a pull request.
[git-fabric] Delete a branch.
[git-fabric] Get full details for a commit including changed files.
[git-fabric] Get the content of a file from a repository.
[git-fabric] Get full details for a pull request.
[git-fabric] List branches in a repository.
[git-fabric] List recent commits on a branch.
[git-fabric] List files and directories at a path in a repository.
[git-fabric] List pull requests in a repository.
[git-fabric] List repositories for an org or the authenticated user.
[git-fabric] Merge a pull request.
List branches in a repository with stale detection.
Apply branch protection rules to a repository branch.
Delete stale merged branches from a repository.
Archive a GitHub repository (read-only, reversible).
Create a new GitHub repository.
List GitHub repositories accessible to the token. Optionally filter by org.
Update repository settings (description, homepage, visibility, etc.).
Get Dependabot security alerts for a repository.
Tool descriptions are metadata-heavy ('[git-fabric]' prefix) rather than user-focused. They should explain WHAT the tool does and WHEN to call it, not which subsystem owns it.
Destructive operations (fabric_git_delete_branch, git_steer_branch_reap) lack dry-run confirmation or explicit confirmation-request support in tool definitions. Agents may accidentally delete branches.
Implementation details leaked in descriptions: 'Queues findings to state/cve-queue.jsonl' in fabric_cve_scan. Agents should not need to know about internal state files.
Pagination not fully specified. Tools like fabric_cve_queue accept a 'limit' parameter but return type (whether next_cursor is included) is undocumented. LLMs cannot chain paginated calls reliably.