# Create a dedicated fine-grained GitHub token. Grant repository contents and # metadata read-only; do not grant write permissions. Keep the real file only # at /etc/mike-ai/github-mcp.env with mode 0600. GITHUB_PERSONAL_ACCESS_TOKEN= # Four deliberately bounded repository-reading tools. Do not replace this # with the broad default toolsets unless the resulting schemas were reviewed. GITHUB_TOOLS=search_repositories,get_repository_tree,get_file_contents,search_code GITHUB_READ_ONLY=1