Some dependency vulnerabilities were found. Patch or upgrade packages to raise this score.
- No known CVEs on the package name — but the OSV/NVD coverage for small packages is limited, so a clean lookup does not guarantee a clean dependency tree
Package trust score
This server scores 71/100 (grade B). The biggest gaps are attack history and response hygiene — fixing those will raise your score fastest. Top recommendation: improve attack history score (+~5 pts).
This server scores 71/100 (grade B). The biggest gaps are attack history and response hygiene — fixing those will raise your score fastest. Top recommendation: improve attack history score (+~5 pts).
| Category | Score | Weight | Points |
|---|---|---|---|
| CVE Posture | 86/100 | 28% | +24 |
| Supply Chain & Malware | 74/100 | 15% | +11 |
| Supply Chain | 90/100 | 15% | +14 |
| Authentication | 55/100 | 9% | +5 |
| Transport Security | 60/100 | 9% | +5 |
| Tool Capability | 50/100 | 11% | +6 |
| Attack History | 45/100 | 5% | +2 |
| Response Hygiene | 45/100 | 4% | +2 |
| Mastyf AI Protection | 50/100 | 4% | +2 |
Some dependency vulnerabilities were found. Patch or upgrade packages to raise this score.
Pick a layout and copy markdown, HTML, RST, BBCode, or AsciiDoc for your README.
Fix the issues above, then run a deep scan or publish from your mastyf.ai proxy for a maintainer-verified badge.
Trust score: 71/100 (static scan)
No known CVEs
Verified publisher
Malware/supply-chain heuristics raised flags — review the signals before trusting this package.
Package comes from a trusted publisher with no typosquat signals.
Only basic API-key auth is configured. OAuth or mTLS is stronger for production.
Uses local stdio transport (low network exposure) but no wire encryption if exposed remotely.
Some tools can modify data or run sensitive operations — tighten policy around them.
No attack data observed — static review only or no probe coverage.
Tool responses are not scanned for leaked secrets or PII — enable Response DLP.
Not proxied through Mastyf AI — no runtime policy enforcement or audit trail.
Plain-language findings from the security scan — fix these to improve your score.
The server accepts tool calls without verifying who is calling. In shared or remote setups, attackers could invoke file or system tools directly.
How to fix: Add OAuth 2.1, API keys, or mTLS before exposing this server beyond localhost.
The server talks over local stdin/stdout — low network risk when run on the same machine, but no encryption if tunneled remotely.
How to fix: Keep stdio for local dev; use HTTPS/mTLS or Mastyf AI proxy for remote agents.
Improve attack history score
Enable Mastyf AI Response DLP to prevent data leaks