Some dependency vulnerabilities were found. Patch or upgrade packages to raise this score.
- No known CVEs on the package name — but the OSV/NVD coverage for small packages is limited, so a clean lookup does not guarantee a clean dependency tree
Package trust score
This server scores 70/100 (grade B). The biggest gaps are supply chain and attack history — fixing those will raise your score fastest. Evidence is partial (50% coverage): Behavioral deep-scan produced no runtime data (install/egress hook unavailable). Lower coverage caps the score — re-run with runtime layers enabled for a stronger grade.
This server scores 70/100 (grade B). The biggest gaps are supply chain and attack history — fixing those will raise your score fastest. Evidence is partial (50% coverage): Behavioral deep-scan produced no runtime data (install/egress hook unavailable). Lower coverage caps the score — re-run with runtime layers enabled for a stronger grade.
| Category | Score | Weight | Points |
|---|---|---|---|
| CVE Posture | 86/100 | 15% | +13 |
| Supply Chain & Malware | 70/100 | 20% | +14 |
| Supply Chain | 50/100 | 10% | +5 |
| Authentication | 55/100 | 8% | +4 |
| Transport Security | 60/100 | 5% | +3 |
| Tool Capability | 100/100 | 15% | +15 |
| Attack History | 50/100 | 15% | +8 |
| Response Hygiene | 70/100 | 10% | +7 |
| Mastyf AI Protection | 50/100 | 2% | +1 |
Some dependency vulnerabilities were found. Patch or upgrade packages to raise this score.
Pick a layout and copy markdown, HTML, RST, BBCode, or AsciiDoc for your README.
Fix the issues above, then run a deep scan or publish from your mastyf.ai proxy for a maintainer-verified badge.
Trust score: 70/100 (live scan)
No known CVEs
Unknown publisher
Malware/supply-chain heuristics raised flags — review the signals before trusting this package.
Supply-chain signals need review — verify package name and publisher before trusting.
Only basic API-key auth is configured. OAuth or mTLS is stronger for production.
Uses local stdio transport (low network exposure) but no wire encryption if exposed remotely.
Tool surface is mostly read-only or low risk.
The live probe sent attack payloads but the server returned no clear signals.
Live probe responses were clean — no payload reflection or secret leaks observed.
Not proxied through Mastyf AI — no runtime policy enforcement or audit trail.
Plain-language findings from the security scan — fix these to improve your score.
The scan produced evidence from 50% of its runtime layers. Behavioral deep-scan produced no runtime data (install/egress hook unavailable) — so the differentiated runtime checks could not be verified and the score is capped until they run.
How to fix: Re-run the scan with a reachable live server and a successful behavioral install so egress and attack-probe layers produce data.
The server accepts tool calls without verifying who is calling. In shared or remote setups, attackers could invoke file or system tools directly.
How to fix: Add OAuth 2.1, API keys, or mTLS before exposing this server beyond localhost.
The server talks over local stdin/stdout — low network risk when run on the same machine, but no encryption if tunneled remotely.
How to fix: Keep stdio for local dev; use HTTPS/mTLS or Mastyf AI proxy for remote agents.
The live probe sent 2 malicious payloads and observed no reflections or secret leaks. No exploitable behavior detected.
How to fix: Re-run a live probe after any code change to confirm no regressions.