GitHub builds an immune system for AI coding agents running on MCP

TL;DR AI
2 min readKey summary
GitHub launched dependency scanning for its MCP Server in public preview and made secret scanning generally available.
The new checks extend GitHub security into AI coding-agent workflows that use Model Context Protocol to access repos and services.
By catching vulnerable packages and exposed credentials earlier, the tools aim to reduce risk before code is committed or deployed.
The move adds protections against issues like over-permissioned agents, prompt injection, and leaked secrets in AI-assisted development.
