MCP server that serves knowledge about your components based on your Storybook stories and documentation
lurq
jadenryu · MCP server
Verify npm packages before your AI agent installs them: hallucinations, advisories, API drift.
Not claimed by its maker. Is this yours? Prove it and answer the findings
Maintenance
MaintainedLast commit on the default branch 30 Sep 2026, 0 days before this check on 30 Sep 2026.
Read from the repository's default branch, read at the commit this listing pins.
Release activity only: it says nothing about quality or safety, and a finished small package can be fine without releases. How it is measured
- Command execution is bounded
- inventory
- node child_process (tests/agentLink.test.ts:8)
- node child_process (tests/checkUpgradeLocal.test.ts:9)
- synchronous shell execution (tests/checkUpgradeLocal.test.ts:43)
- node child_process (tests/fixDiff.test.ts:1)
- An inventory of where the code starts another program, not a verdict on this row: whether each one runs a fixed program or whatever it is handed takes a reading by hand.
- Tool description integrity
- nothing to read
- Pattern set 1.0 matched nothing on 2026-10-01, but none of the descriptions the package ships runs to 120 characters, so there was little for a rule to read.
- It reads the descriptions the package ships, not what the server says when it runs, and a clean description is not the same thing as a safe tool.
Published because it was found. A finding is information about where the limits are, not a verdict that the software is unsafe.
What this does not cover
- Everything. Treat it as you would software from anywhere else.
Corrected after a reading by hand on 2026-09-30
- No shipped credentials: the automated note “The scan matched 4 credential-shaped strings in the files at the commit read. Location withheld pending disclosure to the maker.” was withdrawn. Test values in its tests, among them a token-shaped string spelled out from the alphabet, there to check that its own scrubber removes it.
Tool descriptions are read with pattern set v1.0, published with every rule, its sources and how often it has been wrong.
Receipt history: every signed receipt for every version of this listing, and what changed between them.
What it does
Verify npm packages before your AI agent installs them: hallucinations, advisories, API drift.
Compare with
Compare all 4How far this has been checked
Static scanned
- What it establishes
- Its published package, or for a hosted server its source repository at a recorded commit, was read file by file, without running it, by every check in our current scan.
- What it does not
- How it behaves when it runs, or anything the scan does not read yet: several rubric checks, the repository's history, and compiled code in folders named dist or build. For a hosted server, that the endpoint runs the code that was read. The ooruby Index sets out exactly what was read.
- Exactly what was read
- Commit ae24fba60a943eb75634f5cb3c188fd18568f638 of jadenryu/lurq, read over HTTPS. A commit id is a hash over every file it holds, so this names the same files for anyone who checks.
- Authentication
- Auth declared. Its endpoint, as its own server.json declares it at the commit read, asks for a key or a token before it will talk.
Connecting to it
It runs on the maker's servers, so there is nothing to install. Point your client at this endpoint, as its own server.json declares it at commit ae24fba60a94.
- streamable-http
https://api.lurq.run/mcpAsks for Authorization (a secret), sent as a header.
Try the connection first
The same test the directory runs: the MCP handshake, then a request for the tool list, with no credentials and never a tool call, published as scenario set mcp-connection v1.0. It says whether the endpoint answers and what it lists, not what any tool does.
It cannot be tested without credentials: its endpoint asks for Authorization, which only its users have, and this site never sends a credential.
What was read is the repository at that commit. Nothing on this page establishes that the endpoint runs that code: a hosted server can be redeployed from anything. Any account, plan or price it needs is the maker's to set.
Where this came from
- Listed in
- Official MCP registry
- Registry name
- io.github.jadenryu/lurq
- Repository
- jadenryu/lurq
- Commit read
- ae24fba60a94
- Committed
- 2026-09-30
- Read
- 2026-09-30
Named by its own server.json. At the commit read, the repository's server.json names this server, which is the publisher's statement that this is its source. Nothing signed links the endpoint to that commit, so what answers at the endpoint may be built from something else.
The badge, if this is your listing
It renders the current rung (static scanned) and links back here, where what that does and does not establish is one click away. It updates itself as the evidence deepens.
[](https://ooruby.com/market/jadenryu-lurq)About this listing
- Kind
- MCP server
- Category
- Developer tools
- Pricing
- Maker's terms
- Sandbox
- No
- Hosted
- Yes
- Updated
- 2026-09-30
Similar MCP servers
All MCP serversVerification records what our published tests found on a specific version at a specific date. It is not a warranty, and it does not certify that software is free of defects.