GitHub stars are a crude measure, and I trust them for exactly one thing: they are the only public ledger of where builders are actually spending attention. Pull that ledger this week and ai agent governance splits into two columns that will not reconcile. In one column, a single MCP server for Google Ads, Meta Ads and GA4 went from ★1,125 to ★1,745 in thirteen days, and a cluster of agent-governance gateways and audit SDKs pushed code this week with stars in the hundreds. In the other column, the entire advertising-compliance MCP lane contains three repositories. The best of the three has one star.
Both columns are real. The distance between them is the most useful thing an agency can look at right now.
The Ledger, Thirteen Days
Everything below was pulled from the GitHub API on September 13, 2026. The comparison dates are the August 31 and September 7 weekly scans, so each delta is a measured interval rather than a recollection.
| Repository | Aug 31 | Sep 7 | Sep 13 | 13-day change |
|---|---|---|---|---|
| irinabuht12-oss/google-meta-ads-ga4-mcp (Ryze AI) | ★1,125 | ★1,510 | ★1,745 | +620 (+55%) |
| pipeboard-co/meta-ads-mcp | ★1,215 | ★1,242 | ★1,256 | +41 |
| googleads/google-ads-mcp (official) | ★901 | ★919 | ★940 | +39 |
| gomarble-ai/facebook-ads-mcp-server | ★359 | ★362 | ★365 | +6 |
| kLOsk/adloop | ★253 | ★261 | ★264 | +11 |
| adcontextprotocol/adcp | ★241 | ★242 | ★244 | +3 |
| auditsocials/auditsocials-compliance-mcp | ★0 | ★0 | ★0 | 0 |
| kapoost/abzu-governance | ★0 | ★0 | ★0 | 0 |
The Ryze server is the outlier by a factor of fifteen. Its own README says why builders are pulling it: “250+ tools,” one hosted connector at https://connector.get-ryze.ai/mcp, sign-in with a Google or Facebook account, GA4 included. And one comparison row states the pitch against the official tooling as plainly as anything in this market has:
| Read-only access (official Google MCP) | Full read + write across all platforms |
The write tools are named in the README, and they are the operations an agency billable hour is made of: update_campaign, pause_campaign, update_ad_group, pause_ad_group, update_ad, pause_ad, update_keyword_bid, pause_keyword, update_budget, meta_create_campaign, meta_update_campaign, meta_update_adset, meta_update_ad, meta_update_ad_creative. Budgets, bids, pauses, creative swaps, campaign creation — the whole morning check, available as tool calls from a chat window.
That is what +620 stars in thirteen days is buying. Not novelty. Throughput.
Wait. Governance Did Get Funded.
Here is where the brief I started from was too generous to my own argument. The framing I inherited was “the compliance lane grew 0%,” and if you read that as “nobody is funding agent governance,” it is false. The governance lane is funded, active, and pushing code this week. A quick search for mcp governance in repository names and descriptions returns over a thousand results, and the leaders are real products:
agentic-community/mcp-gateway-registry— ★911, pushed September 10. “Enterprise-ready MCP Gateway & Registry that centralizes AI development tools with secure OAuth authentication, dynamic tool discovery, and unified access.”luckyPipewrench/pipelock— ★842, pushed September 13. “Open-source AI agent firewall for MCP security and agent egress.”ThinkWatchProject/ThinkWatch— ★814, pushed September 12. An enterprise bastion host for AI and MCP access with RBAC, audit logs, rate limiting and cost controls.jagmarques/asqav-sdk— ★509, pushed September 13. “Python and TypeScript SDKs for verifiable evidence of AI agent actions. Signed receipts, policy enforcement, audit trails. Works with LangChain, CrewAI, MCP.”TheLunarCompany/lunar— ★493, pushed September 10. “lunar.dev: Agent native MCP Gateway for governance and security.”OWASP/OWASP-MCP-Governance-and-Risk-Project— ★79, pushed September 8. A governance framework for organizations adopting MCP.
The two repositories whose descriptions literally say governance sit at ★509 and ★493. The lane spans ★79 to ★911. So when I say “AI agent governance has 500 stars,” I mean the self-described governance entrants — and I want that stated plainly rather than hidden behind a headline, because the honest version is the more interesting one.
Because look at what these tools govern. Tokens. Egress. Secret scanning. Tool discovery. Access scopes. Rate limits. Receipts for calls. Every one of them is real, and every one of them answers the same question — did this agent’s traffic behave? — at the transport layer.
Not one of them answers which person at your agency approved the budget change on a client account under UK financial-promotion rules.
Two Categories Wearing One Word
This is where “governance” and “audit” stop meaning what a compliance officer means.
Ryze’s README carries a security section worth crediting in full: “Authentication tokens stay local — Authentication tokens are stored on your machine only,” “Read-only by default — Write operations require explicit confirmation,” “Scoped access — Request only the permissions you need.” That is better hygiene than most of this market ships, and it is the right default.
Now read the same page the way an examiner would. Full-text scan of the README — 24,943 characters:
| Term | Hits |
|---|---|
| compliance | 0 |
| approval / approve | 0 |
| governance | 0 |
| jurisdiction | 0 |
| regulated | 0 |
| finance | 0 |
| human | 0 |
| spend limit | 0 |
The four hits for “audit” are all the same thing: a video titled “Google Ads & Meta Ads Account Audit with Claude MCP,” and its description — “Claude analyzes campaign performance, budget efficiency, and targeting gaps… generates a complete audit report with recommendations.” That is an account-health review. It is a lead magnet, and a good one. It is not evidence.
And “explicit confirmation” deserves the same scrutiny the whole write-era has earned. A confirmation is an API parameter. Nothing in the README requires a named human to send it — on a write-enabled workspace the same assistant that composed the call can confirm it. That is a guard against a model picking the wrong account. It is not a record of who decided.
Then there is the detail that makes the gap structural rather than accidental. The Ryze README indexes its own product pages like this:
- Google Ads MCP: tools, prompts, install per client, comparison
- Meta Ads MCP: Facebook and Instagram Ads tools, prompts, install per client
Install per client. The vendor’s own documentation names the client as the unit of the work. It knows an agency is running twenty of them. It has zero vocabulary anywhere on the page for recording which client’s money a call moved, which person authorized it, or what the ad was allowed to say in the jurisdiction it ran in. The unit of work is named and the record of the unit of work does not exist. That is not an oversight in a README. That is the whole category gap in five words.
What the One-Star Repos Actually Check
Credit where it is due, because the advertising-compliance lane is not empty and what is in it is genuine. A GitHub search for advertising compliance mcp restricted to repository names and descriptions returns three repositories, total:
verteqlabs/anchor-compliance-mcp— ★1. “MCP server for Australian advertising compliance scanning (ACCC, TGA, ASIC, AHPRA, ACMA).”DE-BARY-LLC/debary-mcp-compliance— ★1. “A deterministic fair-housing and advertising rule engine for US real-estate listing text.”auditsocials/auditsocials-mcp— ★0. An advertising compliance glossary of “212 platform-policy, DSA/GDPR/FTC terms, CC BY 4.0.”
AuditSocials, the most committed entrant, has three repositories and has been shipping since August 18. All three sit at zero stars: the pre-publish content checker (auditsocials-compliance-mcp), the 212-term policy glossary, and — created August 28, the most recent — an n8n community node so agencies can wire the check into an existing workflow. That last one is the one I would watch. It means the team stopped waiting for people to come to them and started going where the automation already runs, which is the correct instinct.
And notice the tense in every one of those descriptions. Pre-publish. Listing text. Scanning. Every tool in the advertising-compliance lane checks copy before it runs. Rule engines on the way in. Nobody checks the way out — what actually ran, who authorized it, and what the ad said at the time of the claim it is now being asked to support.
Pre-publish compliance is a real job and an agency should have it. It is also the smaller half. A rule engine that stops a non-compliant ad from launching has answered a question you asked before the spend. It has not answered a regulator’s question about the spend that already happened.
The two remaining tracked repos make the same point by contrast. kapoost/abzu-governance — AdCP plan sync, budget-cap enforcement and an audit ledger — sits at ★0 and has not been pushed since September 3. And the vendor that shipped seven write-capable ad MCP servers in a single weekend in late August, Get MCP Ads, is now three weeks in: all eight repositories in its GitHub organization still sit at ★0, last pushes September 1. Twenty-one days after a weekend of engineering that drew a write-up, the org has not moved a single star. The fastest builder on record is also the fastest forgotten, and the stars went to the aggregator with the hosted connector instead.
Put Your Own Stack on the Ledger
Take the four lanes and find your vendor. The point is not that one is bad. It is that each lane answers a different question, and only one of them answers the question a financial regulator asks.
| Layer | What it produces | The question it answers | The question it cannot answer |
|---|---|---|---|
| Write tools | Ad-account mutations | Can an assistant change my campaigns? | Who authorized this change? |
| Agent governance (gateway, firewall, receipts) | Transport evidence — scopes, tokens, egress, signed calls | Did the agent’s traffic behave? | Which client’s account, under which rules? |
| Pre-publish compliance (rule engines, glossaries) | A block before launch | Is this ad allowed to run? | What ran, and what did it say? |
| Operations record | A named approver, a client, a jurisdiction, before/after values, an export | Who is accountable for what ran, and can you show it? | — |
Three questions to ask in order, and stop at the first one the vendor fails:
- When a write is confirmed, who sends the confirmation — a named person, or the agent on a write-enabled workspace?
- Does the vendor’s governance layer sit under the agent or over the decision? A gateway can tell you the call was signed and within scope. It cannot tell you an FCA examiner which human approved the budget change on a UK client account.
- When the answer is “under the agent,” who owns the record over the decision — the vendor whose session the call ran in, or your agency?
Most stacks fail at question two, and it is not a product gap. It is a layer gap, and no amount of gateway stars closes it.
The Layer the Ledger Has No Column For
For the record, and for whatever a GitHub search is worth: the closest thing I found in the entire governance cluster to an approval gate is NayanVangala/adeia — “Let an agent act — inside a fence you set. Spend limits, human approval, and an append-only audit trail for AI agents.” It sits at ★2. Five hundred stars went to governing the transport. Two went to the phrase human approval.
That is the lane Ott was built to sit in, and the honest scope matters here. Ott does not run your MCP server, does not sit inside a vendor’s gateway session, and has published no agent-governance infrastructure of its own. What it records is the layer above the call: Activity Logging with actor attribution — including AI agents attributed by name rather than “the system” — before/after values, timestamped and stored independently of the platform that made the change, with an export that runs in about 90 seconds. A Budget Ledger with named approval gates, so a spend decision is tied to a person and a client rather than a parameter. Agency Hierarchy jurisdiction tags, because a Business Manager holding forty accounts is not a compliance boundary and a client engagement is. And Telegram conversion tracking with CAPI postbacks, so the funnel baseline lives off-platform where no AI answer can rewrite it.
None of that is governance of the agent. All of it is the record of the decision, which is the artifact an examiner asks for and the one no lane in this ledger sells.
Thirteen days, +620 stars on the write lane, +0 on the compliance lane, and ★500-odd quietly spent on governing the pipe. The market has told you exactly which half of the problem is fundable.
The next time a vendor demo shows you a signed receipt for a tool call, ask which of your clients it was for and which named person approved it. If the answer is “the workspace,” you already know which lane you are standing in.
Ott is the compliance-aware operations layer for agencies running Meta ads in regulated verticals — forex and prop firms, iGaming, crypto, signals and high-risk. Flat pricing from $29/month, no per-client add-ons. Start a free trial and put your own operations on the record.