Rubric v1.0 · run 1 · 2026-09-30
The rubric, run by hand
An automated scan had read every listing. Nobody had ever sat down with one package and the rubric and answered each row by reading it. This is that, 30 times: every row answered, and every note the automated scan had published about these listings judged true or false.
How the 30 were chosen: The 925 listings the automated scan had read, ordered by the SHA-256 of their slug, and the first thirty taken. Nobody picked which packages would make the scanner look good. Each was read at the exact version the scan read, from the registry's own archive, as text, and never run.
Automated notes judged
35
on these 30 listings
Read as false
5
withdrawn from their listings
Found only by reading
9
added to their listings, marked as read by hand
Cells reading cannot settle
138
of 330, published as such
What it changed
- The automated notes read as false are no longer shown on those listings; each listing says a note was withdrawn after a reading by hand, and links here.
- The findings only the reading turned up are shown on those listings, marked as read by hand, including rows the automated scan does not run at all.
- malicious-mcp-server was removed from the catalogue. It describes itself as a deliberately malicious server for testing, and a marketplace has no business listing it.
- The command-execution notes turned out to be an inventory of where a program starts another program, not a verdict on the row: every one that was real ran a fixed program. Listing pages now show them as an inventory, and the row as a finding only when a reading found a program run with whatever it was handed.
3 of the 11 rows could not be answered for a single one of the 30 by reading alone (Dependency advisories, Declared egress, Transparency self-certification): they need a maker's declaration, or a dependency tree resolved against an advisory database. That is what decided which rows each kind of evidence can answer, published on the standard.
The automated notes, check by check
| Check | Notes | True | False |
|---|---|---|---|
| Command execution is bounded | 18 | 16 | 2 |
| No shipped credentials | 2 | 0 | 2 |
| Licence and provenance | 9 | 9 | 0 |
| Data handling disclosed | 6 | 5 | 1 |
True means what the note says is so. For command execution that is a smaller claim than it sounds: the note says a program starts another program, and every true one here ran a fixed program, which is what the row asks for. The one that did not was in a package the scan never read far enough to see.
Row by row, across the thirty
| Row | Pass | Partial | Finding | Not applicable | Not answerable |
|---|---|---|---|---|---|
| No shipped credentials | 30 | 0 | 0 | 0 | 0 |
| Dependency advisories | 0 | 0 | 0 | 0 | 30 |
| Behaviour matches the manifest | 0 | 0 | 1 | 0 | 29 |
| Declared egress | 0 | 0 | 0 | 0 | 30 |
| Data handling disclosed | 15 | 7 | 8 | 0 | 0 |
| Licence and provenance | 21 | 0 | 9 | 0 | 0 |
| Transparency self-certification | 0 | 0 | 0 | 0 | 30 |
| URL handling | 0 | 1 | 2 | 16 | 11 |
| Tool description integrity | 25 | 0 | 0 | 2 | 3 |
| Command execution is bounded | 25 | 3 | 1 | 1 | 0 |
| Authentication enforced | 3 | 0 | 2 | 20 | 5 |
The thirty
thelord-mcp-server-docker-npx
npm · 0.4.0A launcher. It starts mcp-server-docker, a Python package installed separately, so the server's own code is not in this package.
- No shipped credentials
- pass
- The automated scan matched no credential shape, and nothing read in this pass contradicted it. Not re-searched by hand.
- Dependency advisories
- not answerable
- Needs the resolved dependency tree matched against an advisory database. Reading the package cannot do that.
- Behaviour matches the manifest
- not answerable
- No maker has declared a manifest, so there is nothing to hold the behaviour against.
- Declared egress
- not answerable
- Nothing is declared. The hosts the code names are an inventory, not the declaration this row asks for.
- Data handling disclosed
- finding
- No statement of what the server reads or sends. The automated check passed on the words network and permissions, which here mean Docker networks and container permissions.
- Licence and provenance
- pass
- LICENSE ships; MIT declared.
- Transparency self-certification
- not answerable
- A maker's own statement, and none has been made.
- URL handling
- not applicable
- No tool in this package: the tools belong to the Python server it launches.
- Tool description integrity
- not answerable
- No tool descriptions here; they are in the Python server it launches, which is not in the package.
- Command execution is bounded
- pass
- Starts the server by trying a fixed list of five commands. Bounded.
- Authentication enforced
- not applicable
- stdio only: a local process with no network endpoint.
The automated notes, judged
- True Command execution is bounded: “node child_process (bin/mcp-server-docker.js:3)”. It does start a process: one of five fixed commands. The row itself passes.
agent-security-scanner-mcp
npm · 4.5.10A security scanner with an MCP mode, shipping its detection rules and a deliberately vulnerable benchmark corpus to test them on.
- No shipped credentials
- pass
- The 19 credential-shaped strings the automated scan counted are all planted: detection rules and a benchmark corpus of deliberately vulnerable files, among them the example key from AWS's own documentation. None is a working credential.
- Dependency advisories
- not answerable
- Needs the resolved dependency tree matched against an advisory database. Reading the package cannot do that.
- Behaviour matches the manifest
- not answerable
- No maker has declared a manifest, so there is nothing to hold the behaviour against.
- Declared egress
- not answerable
- Nothing is declared. The hosts the code names are an inventory, not the declaration this row asks for.
- Data handling disclosed
- pass
- The README says what telemetry it sends, that source code is not sent, and what the optional email prompt sends.
- Licence and provenance
- pass
- LICENSE ships; MIT declared.
- Transparency self-certification
- not answerable
- A maker's own statement, and none has been made.
- URL handling
- not answerable
- 163 code files. The scan tools read take paths and package names, but this pass did not trace every tool.
- Tool description integrity
- pass
- The one match in set 1.0's count is a poisoned sample in its own demo file, which the server does not advertise.
- Command execution is bounded
- partial
- The sites read run fixed programs (its Python analysers) with argument arrays. Twenty files import child_process and not every one was traced.
- Authentication enforced
- not applicable
- stdio; its dashboard binds to 127.0.0.1.
The automated notes, judged
- False No shipped credentials: “The scan matched 19 credential-shaped strings in the published files. Location withheld pending disclosure to the maker.”. Every match is a planted sample in a security scanner's own rules and benchmark corpus.
- True Command execution is bounded: “node child_process (index.js:6)”. The import is real and used; what it runs is a fixed program.
- True Command execution is bounded: “synchronous shell execution (index.js:637)”. Runs Python with an argument array for its benchmark command. Bounded.
- False Command execution is bounded: “eval (pattern_matcher.py:95)”. Text inside a docstring describing a pattern, not a call.
- False Command execution is bounded: “python subprocess (pattern_matcher.py:400)”. Text inside a docstring describing sinks, not a call.
canvas-lms-mcp
npm · 1.30.0An MCP server for Canvas LMS, over stdio or Streamable HTTP.
- No shipped credentials
- pass
- The automated scan matched no credential shape, and nothing read in this pass contradicted it. Not re-searched by hand.
- Dependency advisories
- not answerable
- Needs the resolved dependency tree matched against an advisory database. Reading the package cannot do that.
- Behaviour matches the manifest
- not answerable
- No maker has declared a manifest, so there is nothing to hold the behaviour against.
- Declared egress
- not answerable
- Nothing is declared. The hosts the code names are an inventory, not the declaration this row asks for.
- Data handling disclosed
- pass
- Says which of its 165 tools write to Canvas, that Canvas enforces its own permissions, and that a FERPA mode pseudonymises students.
- Licence and provenance
- pass
- LICENSE ships; MIT declared.
- Transparency self-certification
- not answerable
- A maker's own statement, and none has been made.
- URL handling
- not answerable
- The Canvas address is configuration; whether any tool fetches a caller-supplied URL was not established.
- Tool description integrity
- pass
- Pattern set 1.0 matched nothing in the descriptions it ships.
- Command execution is bounded
- pass
- Starts no process.
- Authentication enforced
- pass
- The HTTP transport implements OAuth with PKCE and compares tokens in constant time. Read, not exercised.
sentry-junior-notion
npm · 0.222.0A skills plugin for Sentry's Junior agent: instructions and a manifest, no server code.
- No shipped credentials
- pass
- The automated scan matched no credential shape, and nothing read in this pass contradicted it. Not re-searched by hand.
- Dependency advisories
- not answerable
- Needs the resolved dependency tree matched against an advisory database. Reading the package cannot do that.
- Behaviour matches the manifest
- not answerable
- No maker has declared a manifest, so there is nothing to hold the behaviour against.
- Declared egress
- not answerable
- Nothing is declared. The hosts the code names are an inventory, not the declaration this row asks for.
- Data handling disclosed
- pass
- Says each user connects their own Notion account by OAuth and that no shared token is used.
- Licence and provenance
- pass
- LICENSE ships, though package.json declares no licence.
- Transparency self-certification
- not answerable
- A maker's own statement, and none has been made.
- URL handling
- not applicable
- No code.
- Tool description integrity
- not applicable
- No tool descriptions: it points the agent at Notion's hosted MCP server.
- Command execution is bounded
- not applicable
- No code.
- Authentication enforced
- not applicable
- No code.
profullstack-nichedb
npm · 0.30.0A command-line client and stdio MCP bridge for the API of a NicheDB deployment.
- No shipped credentials
- pass
- The automated scan matched no credential shape, and nothing read in this pass contradicted it. Not re-searched by hand.
- Dependency advisories
- not answerable
- Needs the resolved dependency tree matched against an advisory database. Reading the package cannot do that.
- Behaviour matches the manifest
- not answerable
- No maker has declared a manifest, so there is nothing to hold the behaviour against.
- Declared egress
- not answerable
- Nothing is declared. The hosts the code names are an inventory, not the declaration this row asks for.
- Data handling disclosed
- finding
- The 757-character README names the API it talks to and says nothing about what it sends.
- Licence and provenance
- finding
- No licence file ships. package.json declares MIT, whose notice is meant to travel with every copy.
- Transparency self-certification
- not answerable
- A maker's own statement, and none has been made.
- URL handling
- not applicable
- Talks to the one API it is configured with; no tool takes a URL.
- Tool description integrity
- pass
- Pattern set 1.0 matched nothing in the descriptions it ships.
- Command execution is bounded
- pass
- One process: it opens the user's own $VISUAL or $EDITOR on a file. Bounded.
- Authentication enforced
- not applicable
- stdio only: a local process with no network endpoint.
The automated notes, judged
- True Command execution is bounded: “node child_process (src/index.js:12)”. Real, and bounded: it opens the user's editor.
- True Command execution is bounded: “synchronous shell execution (src/index.js:802)”. The same editor launch. The row passes.
- True Licence and provenance: “no LICENCE file at the root (.)”. None ships, though MIT is declared.
- True Data handling disclosed: “no statement of what it reads, writes or sends (README.md)”. There is none.
claude-flow-cli
npm · 3.43.0An agent orchestration command-line tool with an MCP server among many parts: 425 code files.
- No shipped credentials
- pass
- The automated scan matched no credential shape, and nothing read in this pass contradicted it. Not re-searched by hand.
- Dependency advisories
- not answerable
- Needs the resolved dependency tree matched against an advisory database. Reading the package cannot do that.
- Behaviour matches the manifest
- not answerable
- No maker has declared a manifest, so there is nothing to hold the behaviour against.
- Declared egress
- not answerable
- Nothing is declared. The hosts the code names are an inventory, not the declaration this row asks for.
- Data handling disclosed
- partial
- Says personal data is stripped before a federation message leaves; says nothing of what the MCP server itself reads or sends.
- Licence and provenance
- finding
- No licence file ships; MIT declared.
- Transparency self-certification
- not answerable
- A maker's own statement, and none has been made.
- URL handling
- finding
- Its browser tools navigate to any URL they are given, internal addresses included. On your own machine that is a browser tool's job; the row exists for servers that run somewhere shared.
- Tool description integrity
- pass
- Pattern set 1.0 matched nothing in the descriptions it ships.
- Command execution is bounded
- partial
- The sites read run fixed programs: npx with a pinned package, node with a resolved script, ps. Two fetch and run a pinned package from npm at run time. Not every site was traced.
- Authentication enforced
- not answerable
- Its HTTP transports bind to localhost by default; enforcement on every path was not traced across 425 files.
The automated notes, judged
- True Command execution is bounded: “node child_process (plugins/ruflo-metaharness/scripts/_darwin.mjs:35)”. Real; runs npx with a pinned package.
- True Command execution is bounded: “synchronous shell execution (plugins/ruflo-metaharness/scripts/_darwin.mjs:80)”. npx -y with a pinned package: fixed, though it downloads code to run.
- True Command execution is bounded: “node child_process (plugins/ruflo-metaharness/scripts/_harness.mjs:42)”. Real; runs node on a resolved script.
- True Command execution is bounded: “synchronous shell execution (plugins/ruflo-metaharness/scripts/_harness.mjs:192)”. node with an argument array. Bounded.
- True Licence and provenance: “no LICENCE file at the root (.)”. None ships, though MIT is declared.
bitbonsai-mcpvault
npm · 0.16.0An MCP server over a local Obsidian vault.
- No shipped credentials
- pass
- The automated scan matched no credential shape, and nothing read in this pass contradicted it. Not re-searched by hand.
- Dependency advisories
- not answerable
- Needs the resolved dependency tree matched against an advisory database. Reading the package cannot do that.
- Behaviour matches the manifest
- not answerable
- No maker has declared a manifest, so there is nothing to hold the behaviour against.
- Declared egress
- not answerable
- Nothing is declared. The hosts the code names are an inventory, not the declaration this row asks for.
- Data handling disclosed
- pass
- Works on the vault path it is given, and has a read-only mode that removes every tool that writes.
- Licence and provenance
- pass
- LICENSE ships; MIT declared.
- Transparency self-certification
- not answerable
- A maker's own statement, and none has been made.
- URL handling
- not applicable
- No tool takes a URL.
- Tool description integrity
- pass
- Pattern set 1.0 matched nothing in the descriptions it ships.
- Command execution is bounded
- pass
- Starts no process.
- Authentication enforced
- not applicable
- stdio only: a local process with no network endpoint.
aashari-mcp-server-atlassian-confluence
npm · 3.3.0An MCP server for Atlassian Confluence, over stdio by default or HTTP when asked.
- No shipped credentials
- pass
- The automated scan matched no credential shape, and nothing read in this pass contradicted it. Not re-searched by hand.
- Dependency advisories
- not answerable
- Needs the resolved dependency tree matched against an advisory database. Reading the package cannot do that.
- Behaviour matches the manifest
- not answerable
- No maker has declared a manifest, so there is nothing to hold the behaviour against.
- Declared egress
- not answerable
- Nothing is declared. The hosts the code names are an inventory, not the declaration this row asks for.
- Data handling disclosed
- pass
- Says it never sends your data to third parties and only reaches what your token can.
- Licence and provenance
- finding
- No licence file ships; ISC declared.
- Transparency self-certification
- not answerable
- A maker's own statement, and none has been made.
- URL handling
- not answerable
- Tools take API paths on the configured site; whether a path can leave that site was not traced.
- Tool description integrity
- pass
- Pattern set 1.0 matched nothing in the descriptions it ships.
- Command execution is bounded
- pass
- Starts no process.
- Authentication enforced
- finding
- The HTTP transport, switched on with TRANSPORT_MODE=http, listens on every network interface with open CORS and no authentication, and acts with the operator's Atlassian token. The default, stdio, is not affected.
The automated notes, judged
- True Licence and provenance: “no LICENCE file at the root (.)”. None ships, though ISC is declared.
cognitionai-metabase-mcp-server
npm · 2.2.0An MCP server for a Metabase instance.
- No shipped credentials
- pass
- The automated scan matched no credential shape, and nothing read in this pass contradicted it. Not re-searched by hand.
- Dependency advisories
- not answerable
- Needs the resolved dependency tree matched against an advisory database. Reading the package cannot do that.
- Behaviour matches the manifest
- not answerable
- No maker has declared a manifest, so there is nothing to hold the behaviour against.
- Declared egress
- not answerable
- Nothing is declared. The hosts the code names are an inventory, not the declaration this row asks for.
- Data handling disclosed
- partial
- Says it gives the assistant access to your Metabase and offers a read-only mode; says nothing of what leaves it.
- Licence and provenance
- pass
- LICENSE ships; MIT declared.
- Transparency self-certification
- not answerable
- A maker's own statement, and none has been made.
- URL handling
- not answerable
- Not traced.
- Tool description integrity
- pass
- Pattern set 1.0 matched nothing in the descriptions it ships.
- Command execution is bounded
- pass
- Starts no process.
- Authentication enforced
- not applicable
- stdio only: a local process with no network endpoint.
zenlink-mcp
pypi · 2.0.3Drives a Zen browser through a bridge on 127.0.0.1:8765, which is installed separately.
- No shipped credentials
- pass
- The automated scan matched no credential shape, and nothing read in this pass contradicted it. Not re-searched by hand.
- Dependency advisories
- not answerable
- Needs the resolved dependency tree matched against an advisory database. Reading the package cannot do that.
- Behaviour matches the manifest
- not answerable
- No maker has declared a manifest, so there is nothing to hold the behaviour against.
- Declared egress
- not answerable
- Nothing is declared. The hosts the code names are an inventory, not the declaration this row asks for.
- Data handling disclosed
- finding
- No statement of what it reads or sends. The automated check passed on a heading, "Network, cookies, state", which names a group of tools.
- Licence and provenance
- pass
- LICENSE ships; MIT declared.
- Transparency self-certification
- not answerable
- A maker's own statement, and none has been made.
- URL handling
- finding
- zen_navigate and the tab tools open any URL, internal addresses included. A browser on your own machine is meant to; the row exists for servers that run somewhere shared.
- Tool description integrity
- pass
- Read by hand, since the extractor does not read Python: set 1.0 matched nothing across 104 tool docstrings.
- Command execution is bounded
- pass
- Starts no process.
- Authentication enforced
- not applicable
- stdio only: a local process with no network endpoint.
kubernetes-mcp-server-pypi
pypi · 0.0.67A Python wrapper that runs the compiled Go binary of kubernetes-mcp-server shipped inside it.
- No shipped credentials
- pass
- The automated scan matched no credential shape, and nothing read in this pass contradicted it. Not re-searched by hand.
- Dependency advisories
- not answerable
- Needs the resolved dependency tree matched against an advisory database. Reading the package cannot do that.
- Behaviour matches the manifest
- not answerable
- No maker has declared a manifest, so there is nothing to hold the behaviour against.
- Declared egress
- not answerable
- Nothing is declared. The hosts the code names are an inventory, not the declaration this row asks for.
- Data handling disclosed
- pass
- Says tokens, keys and passwords are redacted before reaching the client, and offers read-only and non-destructive modes.
- Licence and provenance
- finding
- No licence file ships; Apache-2.0 declared.
- Transparency self-certification
- not answerable
- A maker's own statement, and none has been made.
- URL handling
- not answerable
- The server is a compiled binary and cannot be read as text.
- Tool description integrity
- not answerable
- Its tool descriptions are inside the compiled binary.
- Command execution is bounded
- pass
- Runs its own bundled binary with the arguments it was given. Bounded.
- Authentication enforced
- not answerable
- The binary cannot be read as text.
The automated notes, judged
- True Command execution is bounded: “python subprocess (kubernetes_mcp_server/kubernetes_mcp_server.py:82)”. Real; it runs the bundled binary.
- True Licence and provenance: “no LICENCE file at the root (.)”. None ships, though Apache-2.0 is declared.
malicious-mcp-server
npm · 1.5.0Says so itself: a deliberately malicious MCP server for end-to-end testing. Removed from the catalogue after this run.
- No shipped credentials
- pass
- The automated scan matched no credential shape, and nothing read in this pass contradicted it. Not re-searched by hand.
- Dependency advisories
- not answerable
- Needs the resolved dependency tree matched against an advisory database. Reading the package cannot do that.
- Behaviour matches the manifest
- finding
- Its own descriptions contradict its code: a tool described as adding two numbers returns code, and others ask for API keys, passwords, card and social security numbers and reply that they have been leaked.
- Declared egress
- not answerable
- Nothing is declared. The hosts the code names are an inventory, not the declaration this row asks for.
- Data handling disclosed
- finding
- No statement.
- Licence and provenance
- finding
- No licence file ships; MIT declared.
- Transparency self-certification
- not answerable
- A maker's own statement, and none has been made.
- URL handling
- not applicable
- No tool takes a URL.
- Tool description integrity
- pass
- Nothing in its descriptions matches set 1.0: the attack is in what the tools return, an instruction override and invisible characters among it. A clean description is not a safe tool, which is the limit this row states.
- Command execution is bounded
- pass
- Starts no process.
- Authentication enforced
- not applicable
- stdio only: a local process with no network endpoint.
The automated notes, judged
- True Licence and provenance: “no LICENCE file at the root (.)”. None ships.
- True Data handling disclosed: “no statement of what it reads, writes or sends (README.md)”. There is none.
formlab-mcp
npm · 0.6.36A read-only MCP server over a local FormLab database.
- No shipped credentials
- pass
- The automated scan matched no credential shape, and nothing read in this pass contradicted it. Not re-searched by hand.
- Dependency advisories
- not answerable
- Needs the resolved dependency tree matched against an advisory database. Reading the package cannot do that.
- Behaviour matches the manifest
- not answerable
- No maker has declared a manifest, so there is nothing to hold the behaviour against.
- Declared egress
- not answerable
- Nothing is declared. The hosts the code names are an inventory, not the declaration this row asks for.
- Data handling disclosed
- pass
- Says the recipes stay on your laptop and only the model's answer travels.
- Licence and provenance
- finding
- No licence file ships; MIT declared.
- Transparency self-certification
- not answerable
- A maker's own statement, and none has been made.
- URL handling
- not applicable
- No tool takes a URL.
- Tool description integrity
- pass
- Pattern set 1.0 matched nothing in the descriptions it ships.
- Command execution is bounded
- pass
- Starts no process.
- Authentication enforced
- not applicable
- stdio only: a local process with no network endpoint.
The automated notes, judged
- True Licence and provenance: “no LICENCE file at the root (.)”. None ships, though MIT is declared.
hubspot-mcp-server
npm · 0.4.0HubSpot's MCP server for developers building HubSpot apps.
- No shipped credentials
- pass
- The automated scan matched no credential shape, and nothing read in this pass contradicted it. Not re-searched by hand.
- Dependency advisories
- not answerable
- Needs the resolved dependency tree matched against an advisory database. Reading the package cannot do that.
- Behaviour matches the manifest
- not answerable
- No maker has declared a manifest, so there is nothing to hold the behaviour against.
- Declared egress
- not answerable
- Nothing is declared. The hosts the code names are an inventory, not the declaration this row asks for.
- Data handling disclosed
- partial
- Explains the private-app token and recommends read-only scopes; says nothing of what leaves it.
- Licence and provenance
- pass
- LICENSE ships; MIT declared.
- Transparency self-certification
- not answerable
- A maker's own statement, and none has been made.
- URL handling
- not answerable
- Not traced.
- Tool description integrity
- pass
- Pattern set 1.0 matched nothing in the descriptions it ships.
- Command execution is bounded
- pass
- Starts no process.
- Authentication enforced
- not applicable
- stdio only: a local process with no network endpoint.
piotr-agier-google-drive-mcp
npm · 2.12.0An MCP server for Google Drive, Docs, Sheets, Slides and Calendar, over stdio or HTTP.
- No shipped credentials
- pass
- The automated scan matched no credential shape, and nothing read in this pass contradicted it. Not re-searched by hand.
- Dependency advisories
- not answerable
- Needs the resolved dependency tree matched against an advisory database. Reading the package cannot do that.
- Behaviour matches the manifest
- not answerable
- No maker has declared a manifest, so there is nothing to hold the behaviour against.
- Declared egress
- not answerable
- Nothing is declared. The hosts the code names are an inventory, not the declaration this row asks for.
- Data handling disclosed
- pass
- Says where OAuth tokens are stored, which scopes to grant, and that its team store holds refresh tokens and must be treated as a secret.
- Licence and provenance
- pass
- LICENSE ships; MIT declared.
- Transparency self-certification
- not answerable
- A maker's own statement, and none has been made.
- URL handling
- not answerable
- Not traced.
- Tool description integrity
- pass
- Pattern set 1.0 matched nothing in the descriptions it ships.
- Command execution is bounded
- pass
- Starts no process.
- Authentication enforced
- pass
- The HTTP transport sits behind the SDK's bearer-token middleware. Read, not exercised.
mcp-server-sqlite-npx
npm · 0.8.0A Node port of the reference SQLite MCP server, over a database file you name.
- No shipped credentials
- pass
- The automated scan matched no credential shape, and nothing read in this pass contradicted it. Not re-searched by hand.
- Dependency advisories
- not answerable
- Needs the resolved dependency tree matched against an advisory database. Reading the package cannot do that.
- Behaviour matches the manifest
- not answerable
- No maker has declared a manifest, so there is nothing to hold the behaviour against.
- Declared egress
- not answerable
- Nothing is declared. The hosts the code names are an inventory, not the declaration this row asks for.
- Data handling disclosed
- finding
- No statement, though from the code all it touches is the database file it is given.
- Licence and provenance
- pass
- LICENSE ships; ISC declared.
- Transparency self-certification
- not answerable
- A maker's own statement, and none has been made.
- URL handling
- not applicable
- No tool takes a URL.
- Tool description integrity
- pass
- Pattern set 1.0 matched nothing in the descriptions it ships.
- Command execution is bounded
- pass
- Starts no process.
- Authentication enforced
- not applicable
- stdio only: a local process with no network endpoint.
The automated notes, judged
- True Data handling disclosed: “no statement of what it reads, writes or sends (README.md)”. There is none.
bitkyc08-opencodex
npm · 2.64.0A local proxy that routes Codex and Claude Code traffic to other model providers: 1,414 files.
- No shipped credentials
- pass
- The automated scan matched no credential shape, and nothing read in this pass contradicted it. Not re-searched by hand.
- Dependency advisories
- not answerable
- Needs the resolved dependency tree matched against an advisory database. Reading the package cannot do that.
- Behaviour matches the manifest
- not answerable
- No maker has declared a manifest, so there is nothing to hold the behaviour against.
- Declared egress
- not answerable
- Nothing is declared. The hosts the code names are an inventory, not the declaration this row asks for.
- Data handling disclosed
- pass
- Plain that your model traffic goes through it to the providers you configure, and warns that some providers restrict accounts that do this.
- Licence and provenance
- pass
- LICENSE ships; MIT declared.
- Transparency self-certification
- not answerable
- A maker's own statement, and none has been made.
- URL handling
- not answerable
- Not traced across 1,414 files.
- Tool description integrity
- pass
- Pattern set 1.0 matched nothing in the descriptions it ships.
- Command execution is bounded
- partial
- The sites read run fixed programs: launchctl and systemctl probes and its own launcher. Not every site was traced.
- Authentication enforced
- not answerable
- Not traced.
The automated notes, judged
- True Command execution is bounded: “node child_process (src/service-manager-probe.ts:21)”. Real; runs launchctl and systemctl probes.
- True Command execution is bounded: “synchronous shell execution (src/service-manager-probe.ts:150)”. A runner given fixed programs by its callers. Bounded.
- True Command execution is bounded: “synchronous shell execution (src/service-manager-probe.ts:166)”. The same runner for raw output. Bounded.
- True Command execution is bounded: “node child_process (src/update/index.ts:1)”. Real; restarts its own process after an update.
th-memory-mcp
npm · 2.3.0A memory server over a local SQLite file.
- No shipped credentials
- pass
- The automated scan matched no credential shape, and nothing read in this pass contradicted it. Not re-searched by hand.
- Dependency advisories
- not answerable
- Needs the resolved dependency tree matched against an advisory database. Reading the package cannot do that.
- Behaviour matches the manifest
- not answerable
- No maker has declared a manifest, so there is nothing to hold the behaviour against.
- Declared egress
- not answerable
- Nothing is declared. The hosts the code names are an inventory, not the declaration this row asks for.
- Data handling disclosed
- pass
- Says everything stays in one local SQLite file with no network access, that secrets are filtered before storage, and that the file is not encrypted.
- Licence and provenance
- pass
- LICENSE ships; MIT declared.
- Transparency self-certification
- not answerable
- A maker's own statement, and none has been made.
- URL handling
- not applicable
- No tool takes a URL.
- Tool description integrity
- pass
- Pattern set 1.0 matched nothing in the descriptions it ships.
- Command execution is bounded
- pass
- Starts no process.
- Authentication enforced
- not applicable
- stdio only: a local process with no network endpoint.
supabase-mcp-server-supabase
npm · 0.13.0Supabase's MCP server.
- No shipped credentials
- pass
- The automated scan matched no credential shape, and nothing read in this pass contradicted it. Not re-searched by hand.
- Dependency advisories
- not answerable
- Needs the resolved dependency tree matched against an advisory database. Reading the package cannot do that.
- Behaviour matches the manifest
- not answerable
- No maker has declared a manifest, so there is nothing to hold the behaviour against.
- Declared egress
- not answerable
- Nothing is declared. The hosts the code names are an inventory, not the declaration this row asks for.
- Data handling disclosed
- finding
- The published package carries no README at all; the repository's may say more, but a package installed from npm says nothing.
- Licence and provenance
- pass
- LICENSE ships; Apache-2.0 declared.
- Transparency self-certification
- not answerable
- A maker's own statement, and none has been made.
- URL handling
- not answerable
- Not traced.
- Tool description integrity
- pass
- Pattern set 1.0 matched nothing in the descriptions it ships.
- Command execution is bounded
- pass
- Starts no process.
- Authentication enforced
- not answerable
- Its local listeners bind to 127.0.0.1; what they serve was not traced.
The automated notes, judged
- True Data handling disclosed: “no SKILL.md, README or manifest to read a declaration from (.)”. The package ships none.
mcp-server-postgres-multi-schema
npm · 0.1.3A read-only Postgres MCP server with multi-schema support.
- No shipped credentials
- pass
- The automated scan matched no credential shape, and nothing read in this pass contradicted it. Not re-searched by hand.
- Dependency advisories
- not answerable
- Needs the resolved dependency tree matched against an advisory database. Reading the package cannot do that.
- Behaviour matches the manifest
- not answerable
- No maker has declared a manifest, so there is nothing to hold the behaviour against.
- Declared egress
- not answerable
- Nothing is declared. The hosts the code names are an inventory, not the declaration this row asks for.
- Data handling disclosed
- pass
- Says every query runs inside a read-only transaction against the database you connect.
- Licence and provenance
- pass
- LICENSE ships; MIT declared.
- Transparency self-certification
- not answerable
- A maker's own statement, and none has been made.
- URL handling
- not applicable
- No tool takes a URL.
- Tool description integrity
- pass
- Pattern set 1.0 matched nothing in the descriptions it ships.
- Command execution is bounded
- pass
- Starts no process.
- Authentication enforced
- not applicable
- stdio only: a local process with no network endpoint.
mcp-server-sqlite
npm · 0.0.2An SQLite MCP server with separate read and write tools.
- No shipped credentials
- pass
- The automated scan matched no credential shape, and nothing read in this pass contradicted it. Not re-searched by hand.
- Dependency advisories
- not answerable
- Needs the resolved dependency tree matched against an advisory database. Reading the package cannot do that.
- Behaviour matches the manifest
- not answerable
- No maker has declared a manifest, so there is nothing to hold the behaviour against.
- Declared egress
- not answerable
- Nothing is declared. The hosts the code names are an inventory, not the declaration this row asks for.
- Data handling disclosed
- partial
- Describes read and write tools separately; says nothing of anything leaving the machine.
- Licence and provenance
- pass
- LICENSE ships; MIT declared.
- Transparency self-certification
- not answerable
- A maker's own statement, and none has been made.
- URL handling
- not applicable
- No tool takes a URL.
- Tool description integrity
- pass
- Pattern set 1.0 matched nothing in the descriptions it ships.
- Command execution is bounded
- pass
- Starts no process.
- Authentication enforced
- not applicable
- stdio only: a local process with no network endpoint.
cyanheads-openalex-mcp-server
npm · 0.7.16An MCP server over the public OpenAlex research catalogue, over stdio or HTTP.
- No shipped credentials
- pass
- The automated scan matched no credential shape, and nothing read in this pass contradicted it. Not re-searched by hand.
- Dependency advisories
- not answerable
- Needs the resolved dependency tree matched against an advisory database. Reading the package cannot do that.
- Behaviour matches the manifest
- not answerable
- No maker has declared a manifest, so there is nothing to hold the behaviour against.
- Declared egress
- not answerable
- Nothing is declared. The hosts the code names are an inventory, not the declaration this row asks for.
- Data handling disclosed
- pass
- Says where logs go and that telemetry is off unless switched on.
- Licence and provenance
- pass
- LICENSE ships; Apache-2.0 declared.
- Transparency self-certification
- not answerable
- A maker's own statement, and none has been made.
- URL handling
- not applicable
- Queries one configured API; no tool takes a URL to fetch.
- Tool description integrity
- pass
- Pattern set 1.0 matched nothing in the descriptions it ships.
- Command execution is bounded
- pass
- Starts no process.
- Authentication enforced
- not applicable
- Its HTTP mode needs no credentials, and every tool reads a public catalogue: nothing privileged to protect.
iobroker-mcp-server
npm · 1.1.3An MCP server for an ioBroker home-automation install, over HTTP.
- No shipped credentials
- pass
- The automated scan matched no credential shape, and nothing read in this pass contradicted it. Not re-searched by hand.
- Dependency advisories
- not answerable
- Needs the resolved dependency tree matched against an advisory database. Reading the package cannot do that.
- Behaviour matches the manifest
- not answerable
- No maker has declared a manifest, so there is nothing to hold the behaviour against.
- Declared egress
- not answerable
- Nothing is declared. The hosts the code names are an inventory, not the declaration this row asks for.
- Data handling disclosed
- pass
- Says which ioBroker user every request runs as and what each way of authenticating sends.
- Licence and provenance
- pass
- LICENSE ships; MIT declared.
- Transparency self-certification
- not answerable
- A maker's own statement, and none has been made.
- URL handling
- partial
- A network diagnostics tool pings and probes hosts by design, local ones included, to troubleshoot adapters.
- Tool description integrity
- pass
- Pattern set 1.0 matched nothing in the descriptions it ships.
- Command execution is bounded
- pass
- Starts no process.
- Authentication enforced
- pass
- Takes Basic or Bearer credentials; the README warns that the option to accept none belongs only on a trusted network. Read, not exercised.
metaharness
npm · 0.4.16A command-line tool that builds agent harnesses. Not itself an MCP server: MCP appears only when it analyses a repository.
- No shipped credentials
- pass
- The automated scan matched no credential shape, and nothing read in this pass contradicted it. Not re-searched by hand.
- Dependency advisories
- not answerable
- Needs the resolved dependency tree matched against an advisory database. Reading the package cannot do that.
- Behaviour matches the manifest
- not answerable
- No maker has declared a manifest, so there is nothing to hold the behaviour against.
- Declared egress
- not answerable
- Nothing is declared. The hosts the code names are an inventory, not the declaration this row asks for.
- Data handling disclosed
- partial
- Describes its local proxy and its logs; says nothing of what it sends.
- Licence and provenance
- pass
- LICENSE ships; MIT declared.
- Transparency self-certification
- not answerable
- A maker's own statement, and none has been made.
- URL handling
- not applicable
- No MCP tools.
- Tool description integrity
- not applicable
- No MCP tools.
- Command execution is bounded
- pass
- Fixed programs: tar to unpack a proxy it downloads, ps and PowerShell with a process number. Bounded.
- Authentication enforced
- not applicable
- No MCP endpoint.
mcp-tenant-isolation
npm · 2.0.0A static-analysis scanner for multi-tenant code, with a stdio MCP server.
- No shipped credentials
- pass
- The automated scan matched no credential shape, and nothing read in this pass contradicted it. Not re-searched by hand.
- Dependency advisories
- not answerable
- Needs the resolved dependency tree matched against an advisory database. Reading the package cannot do that.
- Behaviour matches the manifest
- not answerable
- No maker has declared a manifest, so there is nothing to hold the behaviour against.
- Declared egress
- not answerable
- Nothing is declared. The hosts the code names are an inventory, not the declaration this row asks for.
- Data handling disclosed
- pass
- Says it runs locally over stdio with no network exposure, and that write tools are hidden unless switched on.
- Licence and provenance
- pass
- LICENSE ships; MIT declared.
- Transparency self-certification
- not answerable
- A maker's own statement, and none has been made.
- URL handling
- not applicable
- No tool takes a URL.
- Tool description integrity
- pass
- Pattern set 1.0 matched nothing in the descriptions it ships.
- Command execution is bounded
- pass
- Starts no process.
- Authentication enforced
- not applicable
- stdio only: a local process with no network endpoint.
moonshot-ai-kimi-code
npm · 2.1.0Moonshot AI's coding agent for the terminal.
- No shipped credentials
- pass
- The 36 credential-shaped strings the automated scan counted are all minified parser code in bundled diagram assets, where the word token comes before a string. None is a credential.
- Dependency advisories
- not answerable
- Needs the resolved dependency tree matched against an advisory database. Reading the package cannot do that.
- Behaviour matches the manifest
- not answerable
- No maker has declared a manifest, so there is nothing to hold the behaviour against.
- Declared egress
- not answerable
- Nothing is declared. The hosts the code names are an inventory, not the declaration this row asks for.
- Data handling disclosed
- finding
- No statement of what it reads or sends.
- Licence and provenance
- pass
- LICENSE ships; MIT declared.
- Transparency self-certification
- not answerable
- A maker's own statement, and none has been made.
- URL handling
- not answerable
- Not traced.
- Tool description integrity
- pass
- Pattern set 1.0 matched nothing in the descriptions it ships.
- Command execution is bounded
- pass
- Its install script starts your login shell once, to read PATH, with a fixed command and a five-second limit. Bounded, and it runs at install time.
- Authentication enforced
- not answerable
- Not traced.
The automated notes, judged
- False No shipped credentials: “The scan matched 36 credential-shaped strings in the published files. Location withheld pending disclosure to the maker.”. Every match is generated parser code in bundled diagram assets, not a credential.
- True Command execution is bounded: “node child_process (scripts/postinstall/reach.mjs:29)”. Real, at install time; a fixed probe of the login shell.
- True Data handling disclosed: “no statement of what it reads, writes or sends (README.md)”. There is none.
raihan0824-mcp-server-kubernetes
npm · 2.8.1A fork of mcp-server-kubernetes that runs kubectl against your cluster, over stdio or, when switched on, SSE.
- No shipped credentials
- pass
- The automated scan matched no credential shape, and nothing read in this pass contradicted it. Not re-searched by hand.
- Dependency advisories
- not answerable
- Needs the resolved dependency tree matched against an advisory database. Reading the package cannot do that.
- Behaviour matches the manifest
- not answerable
- No maker has declared a manifest, so there is nothing to hold the behaviour against.
- Declared egress
- not answerable
- Nothing is declared. The hosts the code names are an inventory, not the declaration this row asks for.
- Data handling disclosed
- partial
- Says it runs kubectl against your cluster; says nothing of what leaves it.
- Licence and provenance
- pass
- LICENSE ships; MIT declared.
- Transparency self-certification
- not answerable
- A maker's own statement, and none has been made.
- URL handling
- not applicable
- No tool takes a URL.
- Tool description integrity
- pass
- Pattern set 1.0 matched nothing in the descriptions it ships.
- Command execution is bounded
- finding
- Tool arguments such as the pod name and namespace are written into shell command strings run with execSync. That is the pattern the original package fixed in version 2.5.0 (CVE-2025-53355); this fork still has it. The automated scan missed it because it does not read dist/, which is the only code the package ships.
- Authentication enforced
- finding
- The SSE transport, switched on with ENABLE_UNSAFE_SSE_TRANSPORT, listens on every interface with no authentication. Its own comment calls it unsafe.
rui-branco-jira-mcp
npm · 1.7.12A Jira and Confluence MCP server over stdio.
- No shipped credentials
- pass
- The automated scan matched no credential shape, and nothing read in this pass contradicted it. Not re-searched by hand.
- Dependency advisories
- not answerable
- Needs the resolved dependency tree matched against an advisory database. Reading the package cannot do that.
- Behaviour matches the manifest
- not answerable
- No maker has declared a manifest, so there is nothing to hold the behaviour against.
- Declared egress
- not answerable
- Nothing is declared. The hosts the code names are an inventory, not the declaration this row asks for.
- Data handling disclosed
- finding
- Says API tokens are stored locally. Does not say that at every start it asks npm for a newer version and, if there is one, reinstalls itself globally without asking.
- Licence and provenance
- finding
- No licence file ships; MIT declared.
- Transparency self-certification
- not answerable
- A maker's own statement, and none has been made.
- URL handling
- not answerable
- Tools take Jira and Confluence identifiers on configured sites; not traced further.
- Tool description integrity
- pass
- Pattern set 1.0 matched nothing in the descriptions it ships.
- Command execution is bounded
- pass
- One process: a fixed npm install -g of itself, through a shell, when npm has a newer version. Bounded, and undisclosed.
- Authentication enforced
- not applicable
- stdio only: a local process with no network endpoint.
The automated notes, judged
- True Command execution is bounded: “node child_process (index.js:22)”. Real: the silent self-update.
- True Licence and provenance: “no LICENCE file at the root (.)”. None ships, though MIT is declared.
opentakeoff-mcp
npm · 0.9.87An MCP server that drives a construction takeoff engine over stdio.
- No shipped credentials
- pass
- The automated scan matched no credential shape, and nothing read in this pass contradicted it. Not re-searched by hand.
- Dependency advisories
- not answerable
- Needs the resolved dependency tree matched against an advisory database. Reading the package cannot do that.
- Behaviour matches the manifest
- not answerable
- No maker has declared a manifest, so there is nothing to hold the behaviour against.
- Declared egress
- not answerable
- Nothing is declared. The hosts the code names are an inventory, not the declaration this row asks for.
- Data handling disclosed
- partial
- Explains mounting plans read-only in Docker; says nothing of what leaves it.
- Licence and provenance
- finding
- No licence file ships; Apache-2.0 declared.
- Transparency self-certification
- not answerable
- A maker's own statement, and none has been made.
- URL handling
- not applicable
- Tools take plan files and coordinates, not URLs.
- Tool description integrity
- pass
- Pattern set 1.0 matched nothing in the descriptions it ships.
- Command execution is bounded
- pass
- Starts no process.
- Authentication enforced
- not applicable
- stdio only: a local process with no network endpoint.
The automated notes, judged
- True Licence and provenance: “no LICENCE file at the root (.)”. None ships, though Apache-2.0 is declared.
agentmail-mcp
npm · 1.1.0A stdio bridge to AgentMail's hosted MCP server.
- No shipped credentials
- pass
- The automated scan matched no credential shape, and nothing read in this pass contradicted it. Not re-searched by hand.
- Dependency advisories
- not answerable
- Needs the resolved dependency tree matched against an advisory database. Reading the package cannot do that.
- Behaviour matches the manifest
- not answerable
- No maker has declared a manifest, so there is nothing to hold the behaviour against.
- Declared egress
- not answerable
- Nothing is declared. The hosts the code names are an inventory, not the declaration this row asks for.
- Data handling disclosed
- pass
- Says the API key goes to the hosted server as x-api-key, and that attachments are read and encoded locally before the call is forwarded.
- Licence and provenance
- finding
- No licence file ships; MIT declared.
- Transparency self-certification
- not answerable
- A maker's own statement, and none has been made.
- URL handling
- not applicable
- Forwards to one hosted server; no tool takes a URL.
- Tool description integrity
- not answerable
- Its tools are the hosted server's, fetched at run time; the package holds none to read.
- Command execution is bounded
- pass
- Starts no process.
- Authentication enforced
- not applicable
- stdio locally; the hosted server's authentication is AgentMail's.
The automated notes, judged
- True Licence and provenance: “no LICENCE file at the root (.)”. None ships, though MIT is declared.
- False Data handling disclosed: “no statement of what it reads, writes or sends (README.md)”. The README says exactly what it sends and to whom; it just never uses the words the automated check looks for.
Every credential note in the catalogue, read by hand
The run above read two credential notes and both were false. Two is too few to conclude anything and too many to leave alone, so every listing that carried one was read. 31 listings: 2 true, 29 false. The false ones are withdrawn from their listings, each with the reason printed where the note used to be. Where a match is, is never printed, true or false.
Every listing whose automated note said credential-shaped strings were found, at the version the scan read, each match found again with the same patterns and read in context. A match is true when it is a working credential, or one that cannot be told from one without using it; false when it is a test value, a documented example, a placeholder, a detection rule, or code that merely mentions the shape.
- True neo-mjs: One Google API key, repeated in an example configuration and in tutorial pages, plus a test value. Maps keys are made to sit in web pages and be restricted by referrer; whether this one is restricted cannot be known without using it, and it is not used.
- True oh-my-pi-pi-coding-agent: A complete private key ships in the package's source as a debugging key beside a certificate. Whoever installs the package holds it.
- False aiwg: Every match is a regular expression in its own secret-detection rules.
- False monoes-monomindcli: Documentation: a secret-scanning reference table quoting AWS's documented example key, and placeholder key headers in a configuration guide.
- False instar: Documentation for its own credential-leak detector, listing the shapes it looks for.
- False moonshot-ai-kimi-code: Generated parser code in bundled diagram assets, where the word token comes before a string.
- False qwen-code-qwen-code: Generated parser code in bundled diagram assets, where the word token comes before a string.
- False create-agentic-playwright: A template's test data of deliberately invalid logins.
- False openenthrium-oe-mcp: A placeholder in a README configuration example, far too short to be a real Slack token.
- False vectara-mcp: A test value in its API-key tests.
- False awslabs-aws-location-mcp-server: Test values: AWS's documented example key, asserted in its own tests.
- False awslabs-amazon-mq-mcp-server: Test values, marked in the source as allowed.
- False awslabs-dynamodb-mcp-server: A test value and a constant named and marked as a dummy.
- False mcp-platform: Test values in a template's tests, including a key block whose body is the words test key.
- False db-connect-mcp: Code that recognises private-key headers when parsing a key the user supplies.
- False mcp-m365-mgmt: A documentation example: a temporary password beside a john.doe user on an example tenant.
- False fedramp-20x-mcp: Deliberate examples of hard-coded secrets in a compliance scanner's tests and documentation.
- False github-mcp-server: Test values: key blocks whose bodies read MOCK_KEY or TEST_KEY, and a test token.
- False kubectl-mcp-server-pypi: Test values in its tests.
- False yantrikdb-mcp: Test values in its skill-security tests.
- False mcp-workspace: Test values in its token-fingerprint tests.
- False portainer-mcp: A test value in its test helpers.
- False forge-manager-mcp: Test values in its redaction tests.
- False memory-map-mcp: Test values in its redaction tests.
- False local-shell-mcp: A test value in its secret-scanning tests.
- False desplega-ai-agent-swarm: Test values in its secret-scrubbing and extension tests.
- False loki-mode: A docstring in its own secret scanner describing an example key.
- False mcp-gsheets: A README telling you which header lines your own key must include.
- False agent-security-scanner-mcp: Planted samples in a security scanner's detection rules and benchmark corpus, among them the example key from AWS's own documentation.
- False docguard-cli: A validator that recognises AWS's documented example key so as not to report it.
- False cyberchef-mcp: Default placeholder text for the key fields of CyberChef operations, and code that checks a key was entered.
Every credential note on the hosted servers read from source, read by hand
The hosted servers added from their repositories on 30 September were scanned like everything else, and two of them carried a credential note. Both were read before the notes were published. 2 listings: 0 true, 2 false. The false ones are withdrawn from their listings, each with the reason printed where the note used to be. Where a match is, is never printed, true or false.
Every listing added from a repository whose automated note said credential-shaped strings were found, at the commit the scan read, each match found again and read in context, with the value never printed or stored. The same test as the catalogue review: true when it is a working credential, or one that cannot be told from one without using it; false when it is a test value, a documented example, a placeholder, a detection rule, or code that merely mentions the shape.
- False kagura-ai-memory-cloud: Test values throughout its frontend and backend tests: placeholder Slack tokens named for what they stand in for, fixed test passwords and invitation tokens, and a key block whose body is deliberately not a key.
- False jadenryu-lurq: Test values in its tests, among them a token-shaped string spelled out from the alphabet, there to check that its own scrubber removes it.