[mcp-analysis] MCP Structural Analysis - 2026-09-29 #64265
Closed
Replies: 1 comment
|
This discussion has been marked as outdated by GitHub MCP Structural Analysis. A newer discussion is available at Discussion #64484. |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
GitHub MCP structural analysis for 2026-09-29, testing 10 tools across every non-
contexttoolset available toGITHUB_TOKEN. Today's data adds a new run to the 17-day, 170-datapoint rolling window (2026-08-31 → 2026-09-29). Highlights:github_contextand themcpscriptslist_workflowswrapper remain best-in-class (5/5);search_codehit a 429 rate limit again (1/5); and the top-severity slice oflist_code_scanning_alertsshifted composition for the first time in weeks — the opengrep "pr-action" alerts that dominated every measurement since 2026-09-15 are gone from the top 5, replaced by CodeQL Go findings.Executive Summary
github_context/list_workflows: 5/5search_code: 1/5 (429 rate limit)Full Structural Analysis Report
Usefulness Ratings for Agentic Work
github_contextlist_workflows(mcpscripts)get_file_contentslist_pull_requestslist_code_scanning_alertsrule.helptextlist_discussionsget_labelsearch_userslist_issuessearch_codeSchema Analysis
github_contextget_file_contentslist_issueslist_pull_requestslist_workflowslist_code_scanning_alertsrule.helprepeated verbatim per alertlist_discussionsget_labelsearch_userssearch_code(failed)Response Size Analysis
Tool-by-Tool Analysis (Today)
github_contextget_file_contentslist_issueslist_pull_requestslist_workflowslist_code_scanning_alertslist_discussionsget_labelsearch_userssearch_code30-Day Trend Summary
search_code429 failureNotable Finding: Code Scanning Alert Composition Shift
Every measurement from 2026-09-15 through 2026-09-25 showed the same steady-state top-5 alerts: two recurring opengrep "pr-action" workflow findings (
dockerfile-non-sha-pinned-image,github-actions-npm-install-non-deterministic/actions-uv-pip-install-non-deterministic) alongside CodeQL Go findings. Today, for the first time in this window, the opengrep findings are absent from the top 5 by severity/recency ordering — the full top 5 is now exclusively CodeQL (go/allocation-size-overflow×4,go/bad-redirect-check×1). This suggests either remediation of the opengrep-flagged workflow files or a re-triage that lowered their ranking; it does not necessarily mean they were resolved, sincelist_code_scanning_alertswas only queried withperPage=5.Recommendations
github_context,list_workflows(mcpscripts wrapper),get_file_contents(small files),list_pull_requests— clean, low-overhead, actionable.list_issues(integrity-filtered items disappear silently instead of surfacing a redaction placeholder in the array itself),search_code(429 reliability remains the single biggest blocker to agentic use).list_workflows(172 tokens, 5/5) andlist_pull_requests(45 tokens, 4/5) — the fields-filtered, wrapper-clean pattern other tools should emulate.list_code_scanning_alertsremains the single largest per-call cost (avg 8,032 tokens/call over 30 days) due to verbatim-repeatedrule.helpmarkdown; deduplicating help text by rule ID rather than inlining it per-alert-instance would cut this by roughly 4-5x for repeat-rule alert sets.Visualizations
Response Size by Toolset
Usefulness Ratings
Daily Token Trend
Size vs Usefulness
All reactions