Problem
Three planned automations write to the org project board or read security alerts, and all are blocked on the same missing credential: GHSA draft cards (#2462), nightly triage (#2463), and the security sweep (#2542). dependabot-alerts.yml already reads secrets.PROJECT_TOKEN, but the secret does not exist, so the daily sweep files issues it cannot board.
The built-in GITHUB_TOKEN cannot hold organization projects: write, so the board write needs a separate identity. The App's spec currently lives inside #2462's body; this issue gives the prerequisite its own card.
What to create
A GitHub App installed on the modelcontextprotocol org, on the inspector repository only. It is only an identity with permissions: no code and no server. Workflows mint a short-lived installation token from it on each run with actions/create-github-app-token.
| Scope |
Permission |
Needed by |
| Organization |
Projects: read & write |
every board write (#2462, #2463, #2542, the Dependabot sweep) |
| Repository |
Issues: read & write |
filing, labeling and commenting on issues |
| Repository |
Repository security advisories: read |
GHSA draft cards (#2462) |
| Repository |
Dependabot alerts: read |
the Dependabot sweep (#2542) |
| Repository |
Code scanning alerts: read |
the code-scanning sweep (#2542) |
| Repository |
Administration: read (optional) |
makes the sweep's automated-security-fixes check a real assertion instead of UNVERIFIED |
Grant nothing beyond this list. In particular: no Contents write, no Workflows, no Secrets.
Storage
- The App id and private key go in org Actions secrets limited to the
inspector repo (for example INSPECTOR_BOT_APP_ID and INSPECTOR_BOT_PRIVATE_KEY).
- Record the chosen secret names in
AGENTS.md, next to the sweep sections that consume them.
Notes
- This is an org-admin act and stays human-gated. An agent cannot create or install the App.
- The fallback is a fine-grained PAT with the same permissions, stored as
PROJECT_TOKEN. It is quicker to set up, but it is tied to one person and must be rotated by hand. The App is preferred.
Acceptance
Part of tracker #2543. Every board-writing sub-issue there is blocked on this one.
Problem
Three planned automations write to the org project board or read security alerts, and all are blocked on the same missing credential: GHSA draft cards (#2462), nightly triage (#2463), and the security sweep (#2542).
dependabot-alerts.ymlalready readssecrets.PROJECT_TOKEN, but the secret does not exist, so the daily sweep files issues it cannot board.The built-in
GITHUB_TOKENcannot holdorganization projects: write, so the board write needs a separate identity. The App's spec currently lives inside #2462's body; this issue gives the prerequisite its own card.What to create
A GitHub App installed on the
modelcontextprotocolorg, on theinspectorrepository only. It is only an identity with permissions: no code and no server. Workflows mint a short-lived installation token from it on each run withactions/create-github-app-token.automated-security-fixescheck a real assertion instead ofUNVERIFIEDGrant nothing beyond this list. In particular: no Contents write, no Workflows, no Secrets.
Storage
inspectorrepo (for exampleINSPECTOR_BOT_APP_IDandINSPECTOR_BOT_PRIVATE_KEY).AGENTS.md, next to the sweep sections that consume them.Notes
PROJECT_TOKEN. It is quicker to set up, but it is tied to one person and must be rotated by hand. The App is preferred.Acceptance
inspectoronly, with exactly the permissions aboveinspectorAGENTS.mdworkflow_dispatchrun mints a token and reads the board, proving the install before the sweeps depend on itPart of tracker #2543. Every board-writing sub-issue there is blocked on this one.