Known CVEs affect this server. Update dependencies before production use.
Analyzing package security…
Package trust score
This server scores 50/100 (grade C). The biggest gaps are attack history and tool capability — fixing those will raise your score fastest. Evidence is partial (0% coverage): Behavioral deep-scan produced no runtime data (install/egress hook unavailable). Lower coverage caps the score — re-run with runtime layers enabled for a stronger grade. Top recommendation: improve attack history score (+~5 pts).
This server scores 50/100 (grade C). The biggest gaps are attack history and tool capability — fixing those will raise your score fastest. Evidence is partial (0% coverage): Behavioral deep-scan produced no runtime data (install/egress hook unavailable). Lower coverage caps the score — re-run with runtime layers enabled for a stronger grade. Top recommendation: improve attack history score (+~5 pts).
| Category | Score | Weight | Points |
|---|---|---|---|
| CVE Posture | 54/100 | 15% | +8 |
| Supply Chain & Malware | 70/100 | 20% | +14 |
| Supply Chain | 54/100 | 10% | +5 |
| Authentication | 55/100 | 8% | +4 |
| Transport Security | 60/100 | 5% | +3 |
| Tool Capability | 50/100 | 15% | +8 |
| Attack History | 45/100 | 15% | +7 |
| Response Hygiene | 50/100 | 10% | +5 |
| Mastyf AI Protection | 50/100 | 2% | +1 |
Known CVEs affect this server. Update dependencies before production use.
Pick a layout and copy markdown, HTML, RST, BBCode, or AsciiDoc for your README.
Fix the issues above, then run a deep scan or publish from your mastyf.ai proxy for a maintainer-verified badge.
Trust score: 50/100 (live scan)
No known CVEs
Verified publisher
Malware/supply-chain heuristics raised flags — review the signals before trusting this package.
Supply-chain signals need review — verify package name and publisher before trusting.
Only basic API-key auth is configured. OAuth or mTLS is stronger for production.
Uses local stdio transport (low network exposure) but no wire encryption if exposed remotely.
Some tools can modify data or run sensitive operations — tighten policy around them.
No attack data observed — static review only or no probe coverage.
Tool responses are not scanned for leaked secrets or PII — enable Response DLP.
Not proxied through Mastyf AI — no runtime policy enforcement or audit trail.
Plain-language findings from the security scan — fix these to improve your score.
The scan produced evidence from 0% of its runtime layers. Behavioral deep-scan produced no runtime data (install/egress hook unavailable) — so the differentiated runtime checks could not be verified and the score is capped until they run.
How to fix: Re-run the scan with a reachable live server and a successful behavioral install so egress and attack-probe layers produce data.
Advisory GHSA-frvp-7c67-39w9 affects @hono/node-server in the exact dependency tree resolved for this package. This affects @hono/node-server (direct dependency) and is reported by exact-tree npm audit.
How to fix: No automated fix is available from npm — pin a patched version manually or replace the package.
Advisory GHSA-j687-52p2-xcff affects astro in the exact dependency tree resolved for this package. This affects astro (transitive dependency) and is reported by exact-tree npm audit.
How to fix: Update the affected package to the latest patched release.
Advisory GHSA-xr5h-phrj-8vxv affects astro in the exact dependency tree resolved for this package. This affects astro (transitive dependency) and is reported by exact-tree npm audit.
How to fix: Update the affected package to the latest patched release.
Advisory GHSA-8hv8-536x-4wqp affects astro in the exact dependency tree resolved for this package. This affects astro (transitive dependency) and is reported by exact-tree npm audit.
How to fix: Update the affected package to the latest patched release.
Advisory GHSA-2pvr-wf23-7pc7 affects astro in the exact dependency tree resolved for this package. This affects astro (transitive dependency) and is reported by exact-tree npm audit.
How to fix: Update the affected package to the latest patched release.
Advisory GHSA-jrpj-wcv7-9fh9 affects astro in the exact dependency tree resolved for this package. This affects astro (transitive dependency) and is reported by exact-tree npm audit.
How to fix: Update the affected package to the latest patched release.
Advisory GHSA-4g3v-8h47-v7g6 affects astro in the exact dependency tree resolved for this package. This affects astro (transitive dependency) and is reported by exact-tree npm audit.
How to fix: Update the affected package to the latest patched release.
Advisory GHSA-f48w-9m4c-m7f5 affects astro in the exact dependency tree resolved for this package. This affects astro (transitive dependency) and is reported by exact-tree npm audit.
How to fix: Update the affected package to the latest patched release.
Advisory GHSA-7pw4-f3q4-r2p2 affects astro in the exact dependency tree resolved for this package. This affects astro (transitive dependency) and is reported by exact-tree npm audit.
How to fix: Update the affected package to the latest patched release.
Advisory GHSA-g7r4-m6w7-qqqr affects esbuild in the exact dependency tree resolved for this package. This affects esbuild (transitive dependency) and is reported by exact-tree npm audit.
How to fix: Update the affected package to the latest patched release.
Advisory GHSA-w3rx-r6r6-pgpr affects image-size in the exact dependency tree resolved for this package. This affects image-size (transitive dependency) and is reported by exact-tree npm audit.
How to fix: No automated fix is available from npm — pin a patched version manually or replace the package.
Advisory GHSA-5p2g-fcmc-qvqq affects image-size in the exact dependency tree resolved for this package. This affects image-size (transitive dependency) and is reported by exact-tree npm audit.
How to fix: No automated fix is available from npm — pin a patched version manually or replace the package.
Advisory GHSA-f88m-g3jw-g9cj affects sharp in the exact dependency tree resolved for this package. This affects sharp (transitive dependency) and is reported by exact-tree npm audit.
How to fix: Update the affected package to the latest patched release.
The server accepts tool calls without verifying who is calling. In shared or remote setups, attackers could invoke file or system tools directly.
How to fix: Add OAuth 2.1, API keys, or mTLS before exposing this server beyond localhost.
The server talks over local stdin/stdout — low network risk when run on the same machine, but no encryption if tunneled remotely.
How to fix: Keep stdio for local dev; use HTTPS/mTLS or Mastyf AI proxy for remote agents.
The runtime probe tried to start the server and probe it with attack payloads, but could not establish a live MCP connection: Handshake timeout. No attack observations were collected.
How to fix: Confirm the package starts an MCP server (some expose it behind a subcommand) and re-run a live probe.
Improve attack history score