Broad scope is what holds it from A, full breakdown here: https://www.opentrustbench.com/r/github-github-mcp-server.html
Badge for your README if you want it:

Registry re-scans weekly, happy to re-run on request. If any finding looks wrong I want to know, false positives are my problem to fix. Tool: https://github.com/eulogik/OpenTrustBench
Broad scope is what holds it from A, full breakdown here: https://www.opentrustbench.com/r/github-github-mcp-server.html
Badge for your README if you want it:
Registry re-scans weekly, happy to re-run on request. If any finding looks wrong I want to know, false positives are my problem to fix. Tool: https://github.com/eulogik/OpenTrustBench