github TypeScript analyzed 8c8f44f

NordenSoft/noa

github

NOA — the Agent Action Receipt. Open governance layer for AI agents: gate risky actions before they run, emit a tamper-evident receipt anyone can verify offline. Early access · Apache-2.0.

maintainer
NordenSoft
licence
Apache-2.0
first seen
2026-08-14
last seen
2026-08-28
releases · 30d
0
short id

NordenSoft/noa is an MCP server distributed on github, maintained by NordenSoft, tracked here since August 2026. It has shipped 4 releases and exposes 3 tools. Tools include echo, read_data, transfer_funds. Its composite risk grade is D — an inferred review prompt computed from observed signals, not a verdict. 1 known CVE on file.

what we found

1 advisory published against this server still applies to the version it ships, the most severe rated critical, most recently 2026-08-03.

Reading the source raised one review prompt — dangerous code — each a pattern worth a human look rather than a finding of fault.

Its 3 tools appear to reach filesystem, shell / exec, network and secrets, inferred from tool names, descriptions and input schemas rather than from observed behaviour.

full security breakdown →
tools 3
  • echo
  • read_data
  • transfer_funds
release cadence · 90d 4 releases
06-18 00:00 08-01 00:00 now
recent releases last 4
version date src
v0.6.0 2026-08-04 github
v0.5.0 2026-08-04 github
v0.4.0 2026-07-10 github
v0.3.0 2026-07-09 github

view all →