GitHub Coding Agent Authorisation
Coding agents have a high blast radius. A compromised or misbehaving agent can merge code, alter infrastructure-as-code, introduce vulnerabilities or access CI/CD secrets. The GitHub pilot routes the agent through an MCP doorkeeper instead of giving it standing credentials.
- T0read PR metadata / CI status
- T1create branch / comment / low-risk change
- T2merge to main with passkey approval
- T3force push / CI bypass / branch protection change with liveness approval