MCP server that lets agents work on GitHub PR reviews behind a safety boundary: pending (draft) reviews by default, submitting as an explicit opt-in
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts — it cannot prove the absence of malicious code.
MCP server that lets agents work on GitHub PR reviews behind a safety boundary: pending (draft) reviews by default, submitting as an explicit opt-in