Dependencies look clean — no known critical vulnerabilities were found.
- No known CVEs — excellent posture
Package trust score
This server scores 72/100 (grade B). The biggest gaps are tool capability and attack history — fixing those will raise your score fastest.
This server scores 72/100 (grade B). The biggest gaps are tool capability and attack history — fixing those will raise your score fastest.
| Category | Score | Weight | Points |
|---|---|---|---|
| CVE Posture | 100/100 | 25% | +25 |
| Authentication | 70/100 | 15% | +11 |
| Transport Security | 75/100 | 15% | +11 |
| Tool Capability | 50/100 | 12% | +6 |
| Supply Chain | 75/100 | 12% | +9 |
| Attack History | 50/100 | 10% | +5 |
| Response Hygiene | 50/100 | 6% | +3 |
| Mastyf AI Protection | 50/100 | 5% | +3 |
Dependencies look clean — no known critical vulnerabilities were found.
Callers must authenticate before using tools — good for multi-user or remote setups.
Pick a layout and copy markdown, HTML, RST, BBCode, or AsciiDoc for your README.
Fix the issues above, then run a deep scan or publish from your mastyf.ai proxy for a maintainer-verified badge.
Trust score: 72/100 (live scan)
No known CVEs
Unknown publisher
Traffic is encrypted in transit (HTTPS or mTLS).
Some tools can modify data or run sensitive operations — tighten policy around them.
Supply-chain signals need review — verify package name and publisher before trusting.
No attack data observed — static review only or no probe coverage.
Tool responses are not scanned for leaked secrets or PII — enable Response DLP.
Not proxied through Mastyf AI — no runtime policy enforcement or audit trail.
Plain-language findings from the security scan — fix these to improve your score.
The server accepts tool calls without verifying who is calling. In shared or remote setups, attackers could invoke file or system tools directly.
How to fix: Add OAuth 2.1, API keys, or mTLS before exposing this server beyond localhost.
The server talks over local stdin/stdout — low network risk when run on the same machine, but no encryption if tunneled remotely.
How to fix: Keep stdio for local dev; use HTTPS/mTLS or Mastyf AI proxy for remote agents.
The deep scan tried to start the server and probe it with attack payloads, but could not establish a live MCP connection: Process exited with code 1. No attack observations were collected.
How to fix: Confirm the package starts an MCP server (some expose it behind a subcommand) and re-run a deep scan.