Some dependency vulnerabilities were found. Patch or upgrade packages to raise this score.
Analyzing package security…
Package trust score
This server scores 50/100 (grade C). The biggest gaps are supply chain and attack history — fixing those will raise your score fastest. Evidence is partial (0% coverage): Behavioral deep-scan produced no runtime data (install/egress hook unavailable). Lower coverage caps the score — re-run with runtime layers enabled for a stronger grade. Top recommendation: switch to a trusted publisher package and enable dependency verification (+~9 pts).
This server scores 50/100 (grade C). The biggest gaps are supply chain and attack history — fixing those will raise your score fastest. Evidence is partial (0% coverage): Behavioral deep-scan produced no runtime data (install/egress hook unavailable). Lower coverage caps the score — re-run with runtime layers enabled for a stronger grade. Top recommendation: switch to a trusted publisher package and enable dependency verification (+~9 pts).
| Category | Score | Weight | Points |
|---|---|---|---|
| CVE Posture | 80/100 | 15% | +12 |
| Supply Chain & Malware | 70/100 | 20% | +14 |
| Supply Chain | 10/100 | 10% | +1 |
| Authentication | 55/100 | 8% | +4 |
| Transport Security | 60/100 | 5% | +3 |
| Tool Capability | 100/100 | 15% | +15 |
| Attack History | 45/100 | 15% | +7 |
| Response Hygiene | 50/100 | 10% | +5 |
| Mastyf AI Protection | 50/100 | 2% | +1 |
Some dependency vulnerabilities were found. Patch or upgrade packages to raise this score.
Pick a layout and copy markdown, HTML, RST, BBCode, or AsciiDoc for your README.
Fix the issues above, then run a deep scan or publish from your mastyf.ai proxy for a maintainer-verified badge.
Trust score: 50/100 (live scan)
No known CVEs
Unknown publisher
Malware/supply-chain heuristics raised flags — review the signals before trusting this package.
Supply-chain signals need review — verify package name and publisher before trusting.
Only basic API-key auth is configured. OAuth or mTLS is stronger for production.
Uses local stdio transport (low network exposure) but no wire encryption if exposed remotely.
Tool surface is mostly read-only or low risk.
No attack data observed — static review only or no probe coverage.
Tool responses are not scanned for leaked secrets or PII — enable Response DLP.
Not proxied through Mastyf AI — no runtime policy enforcement or audit trail.
Plain-language findings from the security scan — fix these to improve your score.
The scan produced evidence from 0% of its runtime layers. Behavioral deep-scan produced no runtime data (install/egress hook unavailable) — so the differentiated runtime checks could not be verified and the score is capped until they run.
How to fix: Re-run the scan with a reachable live server and a successful behavioral install so egress and attack-probe layers produce data.
The server accepts tool calls without verifying who is calling. In shared or remote setups, attackers could invoke file or system tools directly.
How to fix: Add OAuth 2.1, API keys, or mTLS before exposing this server beyond localhost.
The server talks over local stdin/stdout — low network risk when run on the same machine, but no encryption if tunneled remotely.
How to fix: Keep stdio for local dev; use HTTPS/mTLS or Mastyf AI proxy for remote agents.
Package name "context-mcp" closely resembles "@upstash/context7-mcp" — this can be a supply-chain trick.
How to fix: Verify the exact npm scope and publisher before installing or certifying.
Package name "@autodev/context-mcp" closely resembles "@upstash/context7-mcp" — this can be a supply-chain trick.
How to fix: Verify the exact npm scope and publisher before installing or certifying.
The runtime probe tried to start the server and probe it with attack payloads, but could not establish a live MCP connection: Handshake timeout. No attack observations were collected.
How to fix: Confirm the package starts an MCP server (some expose it behind a subcommand) and re-run a live probe.
Switch to a trusted publisher package and enable dependency verification
Improve attack history score