security

Security

Every MCP risk signal in one place — CVEs, tool safety, drift, naming, licenses. Heuristic: review signals, not verdicts.

Supply chain: npm packages that run install-lifecycle scripts (code on install) or have been deprecated upstream, alongside ecosystem provenance coverage — review signals inferred from registry metadata, not verdicts.

provenance coverage178/660 npm+pypi
  • with provenance 178

27% of 660 npm + PyPI servers ship a build-provenance attestation.

  1. @aashari/mcp-server-atlassian-confluence install hooks no provenance
    npm
  2. @aashari/mcp-server-atlassian-jira install hooks no provenance
    npm
  3. @aerostack/gateway install hooks no provenance
    npm
  4. @ainative/cody-cli install hooks no provenance
    npm
  5. @askexenow/exe-os install hooks no provenance
    npm
  6. @azure/mcp install hooks no provenance
    npm
  7. @bangdao-ai/acw-tools install hooks no provenance
    npm
  8. @bike4mind/cli install hooks no provenance
    npm
  9. @claude-flow/cli install hooks no provenance
    npm
  10. @exaudeus/workrail install hooks
    npm
  11. @henkey/postgres-mcp-server install hooks no provenance
    npm
  12. @iola_adm/iola-cli install hooks
    npm
  13. @ironbee-ai/cli install hooks no provenance
    npm
  14. @ironbee-ai/devtools install hooks no provenance
    npm
  15. @jelou/cli install hooks no provenance
    npm
  16. @mapbox/mcp-server install hooks no provenance
    npm
  17. @nano-step/nano-brain install hooks no provenance
    npm
  18. @oxis-dev/tessra install hooks no provenance
    npm
  19. @pixelbyte-software/pixcode install hooks no provenance
    npm
  20. @proggarapsody/bitbottle install hooks
    npm
  21. @scp3500/openvl install hooks no provenance
    npm
  22. @tacticlaunch/mcp-linear install hooks no provenance
    npm
  23. @tocodex/cli install hooks no provenance
    npm
  24. @trymesh/cli install hooks no provenance
    npm
  25. @waniwani/sdk install hooks
    npm