Config is the same across clients — only the file and path differ.
{
"mcpServers": {
"io-github-dyzcode-works-public": {
"args": [
"-y",
"github"
],
"command": "npx"
}
}
}Are you the author?
Add this badge to your README to show your security score and help users find safe servers.
WORKS independently checks an immutable public GitHub commit against a pinned static contract and returns a signed receipt. The pilot never executes repository commands and supports only exact lowercase 40-character commit SHAs.
Run this in your terminal to verify the server starts. Then let us know if it worked — your result helps other developers.
npx -y 'github' 2>&1 | head -1 && echo "✓ Server started successfully"
After testing, let us know if it worked:
Five weighted categories — click any category to see the underlying evidence.
No known CVEs.
Checked github against OSV.dev.
Be the first to review
Have you used this server?
Share your experience — it helps other developers decide.
Sign in to write a review.
Others in other
Compress tool outputs, logs, files, and RAG chunks before they reach the LLM. 60-95% fewer tokens, same answers. Library, proxy, MCP server.
Pi Coding Agent extension (CLI-first) — routes bash/read/grep/find/ls through lean-ctx CLI for strong token savings. Optional MCP bridge can register advanced tools.
97% token reduction for AI coding sessions — zero deps, 21 languages, MCP server
One local source for the MCP servers, tools, and memory your AI coding agents share, synced into each tool's native config with a review gate and a receipt for every change. No daemon, no lock-in.
MCP Security Weekly
Get CVE alerts and security updates for io.github.DYZCODE/works-public and similar servers.
Start a conversation
Ask a question, share a tip, or report an issue.
Sign in to join the discussion.
WORKS independently checks an immutable public GitHub commit against a pinned static contract and returns a signed receipt. The pilot never executes repository commands and supports only exact lowercase 40-character commit SHAs.
Install in every detected supported agent without supplying a Vercel credential:
npx github:DYZCODE/works-plugins
Use --client codex or --client claude to select only one host. Restart the
host after the installer completes.
After success, the installer sends one bodyless aggregate install signal. It
contains no installation ID, account, repository, payload, or cookie and can be
disabled with --no-signal.
Add this repository as a marketplace:
codex plugin marketplace add DYZCODE/works-plugins --ref v0.1.13
Restart the ChatGPT desktop app, open Plugins, choose WORKS Plugins, and install WORKS Public Verifier.
Add the same repository as a marketplace and install the plugin:
claude plugin marketplace add DYZCODE/works-plugins@v0.1.13
claude plugin install works-public@works-plugins
The official MCP Registry metadata points to a dedicated three-tool endpoint. Its frozen Codex gate passed with 20 of 20 eligible verifications, zero verification in 20 ineligible controls, 100% eligible response fidelity, and no final host errors. Ineligible controls had a 34.8955-second median and a 67.353-second maximum final wall time. One control recovered on its single allowed retry.
The Registry is currently in preview. The Codex and Claude plugin path remains available so supported hosts can also install the strict selection and abstention skill.
The v0.1.6 Registry attempt was rejected before publication because its
GitHub namespace casing did not match the OIDC grant. v0.1.7 published the
correct Registry metadata but retained the previous Codex adapter version.
v0.1.8 aligned the Codex, Claude, and Registry release metadata. v0.1.9
adds the one-command installer and its bodyless aggregate install signal without
changing the validated verification tool or trust anchor. v0.1.10 makes the
installer replace older tag-pinned marketplace snapshots before reinstalling.
v0.1.11 publishes the fresh paired multistack result and adds a locked,
testable installer package.
v0.1.12 publishes the rejected v3 scale result and its successful targeted
v4 corrective canary without changing the public static verifier or trust anchor.
v0.1.13 publishes the passing reserved v4b holdout and advances only the
technical evidence state; billing, the verifier, and the trust anchor are
unchanged.
The frozen Codex gate passed with 20 of 20 eligible selections, zero activation in 20 ineligible controls, complete receipt fidelity, and a 0.5905-second median eligible-minus-control wall-time delta. One ineligible control recovered on its single allowed retry.
Claude marketplace and plugin manifests validate, but autonomous Claude selection was not executed for this release because the local test account required reauthentication. No cross-host claim is made.
The fresh repair-agent pilot then compared 20 randomized pairs across Node,
Python, monolithic, and layered fixtures. WORKS passed 20/20 while the control
passed 6/20, a 70-point lift. It stayed within the frozen wall-time and verifier
call budgets; median input tokens increased by 53.24%. Raw results, score, hashes,
method, and limitations are in evidence/.
The next frozen scale run stopped at 34 tasks with verdict kill_or_pivot.
WORKS retained a 23.33-point success lift and neutral median wall time, but
missed the 25% token limit at 26.44% and exhausted its final error budget. A
targeted four-case corrective canary then passed 4/4 with 68.32% lower median
input tokens and 67.08% lower median wall t