Skip to main content
Connect a GitHub account to scan its repositories from the platform and get automatic pull request scans.
A GitHub account connects to one AgentGG organization at a time. If it is already connected to another organization, uninstall the AgentGG App from that account on GitHub first, then connect it here.

Connect an account

1

Open the GitHub page

Select GitHub in the sidebar.
2

Start the connection

Select Connect repos. GitHub opens in a new tab.
3

Choose repositories

On GitHub, install the AgentGG App on an account, then grant it all repositories or select individual ones.
4

Confirm the connection

GitHub returns you to a confirmation page. Review the account and the repositories listed, then select Connect.
The account now appears on the GitHub page, with every repository it can access.

Pick repositories and turn on pull request scans

Each connected repository lists four controls: Run scan, Workspaces, Agents, and PR scans. Turn on PR scans for a repository you want scanned on every pull request. Leave it off for a repository you only scan with Run scan. On GitHub, select Add or remove repos on GitHub at any time to change which repositories the AgentGG App can access.

What a check run looks like

Each pull request gets a check named AgentGG security scan. It starts in progress, then completes as: The check’s title names the finding count, for example AgentGG: 3 findings (1 critical, 2 medium). Select the check for a link back to the scan.

What a review comment looks like

The platform also posts each finding as a comment on the changed line it applies to. A comment is collapsed by default. It shows the severity and the title, for example High · SQL injection. Open it to read the summary, details, a proof of concept, impact, and reference links. A summary comment at the top of the review names the total finding count, with a link to the full scan.