The MCP ecosystem often has several independent packages implementing the same tool — and "Git" currently has 16. Every one of them was scanned with the same deterministic engine, so the numbers below are directly comparable: the Trust Score (A–F), the capability blast radius, and how much of the package the scan could actually inspect. They are ranked by score; ties break toward unscoped, longer-established packages.
| Implementation | Package | Trust | Capability | Coverage | Findings | Scanned |
|---|---|---|---|---|---|---|
| Git Source verifiedbest by paretools | @paretools/git
npm |
A 100/100 | Minimal | Source | 0 | 2026-07-22 |
| Git by cyanheads | @cyanheads/git-mcp-server
npm |
A 100/100 | Minimal | Metadata | 0 | 2026-07-22 |
| Git by mseep | @mseep/git-mcp-server
npm |
A 100/100 | High | Source | 10 | 2026-07-22 |
| Git by kwanLeeFrmVi | mcp-git
npm |
A 100/100 | High | Source | 1 | 2026-07-22 |
| Git by raytien | @raytien/git-mcp-server
npm |
A 100/100 | Minimal | Source | 0 | 2026-07-22 |
| Git by selfagency | @selfagency/git-mcp
npm |
A 100/100 | High | Source | 1 | 2026-07-22 |
| Git by liangshanli | @liangshanli/mcp-server-git
npm |
A 100/100 | High | Source | 4 | 2026-07-22 |
| Git by infoinlet | @infoinlet/mcp-git
npm |
A 98/100 | High | Source | 2 | 2026-07-22 |
| Git by jixo | @jixo/mcp-git
npm |
A 98/100 | Minimal | Source | 1 | 2026-07-22 |
| Git (official) by modelcontextprotocol | mcp-server-git
PyPI |
A 98/100 | Minimal | Source | 1 | 2026-07-22 |
| Git by kjozsa | git-mcp
PyPI |
A 98/100 | High | Source | 2 | 2026-07-22 |
| Git by npm | git-mcp-server
npm |
A 98/100 | High | Source | 2 | 2026-07-22 |
| Git by andrebuzeli | @andrebuzeli/git-mcp
npm |
A 98/100 | High | Source | 2 | 2026-07-22 |
| Git by npm | git-mcp
npm |
A 98/100 | High | Source | 3 | 2026-07-22 |
| Git by PyPI | git-mcp-server
PyPI |
A 98/100 | High | Source | 3 | 2026-07-22 |
| Git by christkv | git
npm |
A 94/100 | High | Source | 4 | 2026-07-22 |
A higher-ranked implementation is not "the official one" — ranking reflects only what the deterministic scan found in each published package. Open an implementation to read its individual findings with evidence, its scan history per version, and to grab an embeddable badge. Scores are automated opinions, recomputed on every rescan.