AI inventory

GitHub Copilot

Code · GitHub (demo) GitHub (Microsoft) · Coding · config: Copilot instructions · config: VS Code MCP servers

Policy · none set
Policy changes re-score this app on the next sync, which starts right away.
Finding · Open
Risk score
39
Medium
People
0
Committers are not collected
Repositories
2
0 public · 0 packages
Keys in code
0
None found in the files read
source-codefixturemcp-serverscoding-assistant
Next steps

Recommended actions

  1. 01MCP server configuration is committed in 1 repositories. Review which servers agents can reach; a tool server with write access is an agent with write access.
  2. 02GitHub Copilot is configured for this codebase. Set a policy on AI coding tools: which are approved, whether repository context may leave the company, and whether generated code needs review flags.
GitHub (demo) · fixture

Where it lives in code

Assistant config · 2
Repositories
RepositorySignalsPushed
contoso/customer-portalAssistant config26 h ago
contoso/helpdesk-botAssistant config6 d ago
Configuration
Copilot instructions1 repo
VS Code MCP servers1 repo
Who

People

Identifiers come from device telemetry and proxy logs, so they may be account names rather than full directory entries.

No people are linked to this app.

Why

Evidence

  1. source_code · Sep 13, 2026
    GitHub Copilot in 2 repositories via GitHub (demo): Copilot instructions, VS Code MCP servers
    Detail
    {
      "repos": [
        "contoso/customer-portal",
        "contoso/helpdesk-bot"
      ],
      "configs": [
        {
          "path": "Copilot instructions",
          "repos": 1
        },
        {
          "path": "VS Code MCP servers",
          "repos": 1
        }
      ],
      "packages": [],
      "endpoints": []
    }