github Rust analyzed 940f1b0

dinglebear-ai/soma

github

Batteries-included RMCP runtime and scaffold for shipping Rust MCP servers with CLI/REST/HTTP MCP, auth, providers, plugins, and generated contracts.

maintainer
dinglebear-ai
license
MIT
first seen
2026-07-20
last seen
2026-08-02
releases · 30d
5
short id

Drift inferred · capture-to-capture

  1. HIGH code analysis flagged committed secret in dinglebear-ai/soma
  2. HIGH code analysis flagged committed secret in dinglebear-ai/soma
capabilities 0 tools
transport http verified reported listed in the official MCP registry counts 0 tools · 0 res · 0 prompts permission surface via code analysis

No tools enumerated yet for this server.

skills & danger signals github-tarball
prompt-surface shipped agent-instruction files + hidden-content / dangerous-code findings — quoted from the analyzed source

analyzed commit 940f1b0 · analyzer v28 · 2d ago

skills & prompt files 17

danger signals1

code evidence vv0.7.0 · github-tarball
evidence-backed findings quoted directly from the published source artifact — not inferred

code files: 1174

filesystem 1

  • fs dinglebear-ai-soma-940f1b0/crates/shared/codex-app-server-client/clients/typescript/src/internal/find-binary.ts :6 import { existsSync } from "node:fs";

shell / exec 1

  • shell dinglebear-ai-soma-940f1b0/packages/soma-rmcp/bin/soma-rmcp.js :3 const { spawn } = require("node:child_process");

network 4

  • net dinglebear-ai-soma-940f1b0/apps/web/lib/api.ts :47 const res = await fetch(url, options);
  • net dinglebear-ai-soma-940f1b0/crates/shared/codex-app-server-client/clients/typescript/src/internal/free-port.ts :9 import { createServer } from "node:net";
  • net dinglebear-ai-soma-940f1b0/crates/shared/codex-app-server-client/clients/typescript/src/internal/sse.ts :7 // than through a real `fetch()`/HTTP round trip. `client.ts` imports
  • net dinglebear-ai-soma-940f1b0/crates/soma/web/assets/source/lib/api.ts :47 const res = await fetch(url, options);

install hooks 2

  • prepack dinglebear-ai-soma-940f1b0/packages/soma-rmcp/package.json :58 node scripts/sync-readme.js
  • prepublishOnly dinglebear-ai-soma-940f1b0/packages/soma-rmcp/package.json :60 node scripts/check-package.js --release

declared dependencies 62

  • rmcp@=3.0.0-beta.2
  • @radix-ui/react-slot@^1.2.4
  • @tailwindcss/vite@^4.1.18
  • @tauri-apps/api@^2.10.0
  • ajv@^8.20.0
  • class-variance-authority@^0.7.1
  • clsx@^2.1.1
  • react@^19.2.6
  • react-dom@^19.2.6
  • shiki@3.23.0
  • streamdown@^2.5.0
  • tailwind-merge@^3.4.0
  • tailwindcss@^4.1.18
  • @biomejs/biome@^2.3.0
  • @tauri-apps/cli@^2.10.0
  • @testing-library/jest-dom@^6.9.1
  • @testing-library/react@^16.3.2
  • @testing-library/user-event@^14.6.1
  • @types/jest-axe@^3.5.9
  • @types/react@^19.2.15
  • @types/react-dom@^19.2.3
  • @vitejs/plugin-react@^5.1.2
  • @vitest/coverage-v8@^4.1.9
  • esbuild@^0.28.1
  • jest-axe@^10.0.0
  • jsdom@^29.1.1
  • lucide-react@^1.16.0
  • shadcn@^4.11.0
  • typescript@^5.9.3
  • vite@^8.1.4
  • vitest@^4.1.9
  • rmcp-client@=3.0.0-beta.2
  • pyo3@0.29
  • zeroize@1
  • rmcp-traces@*
  • soma-auth@*
  • soma-cli-core@*
  • soma-codemode@*
  • soma-gateway@*
  • soma-http-api@*
  • soma-http-server@*
  • soma-mcp-client@*
  • mcp-client@*
  • soma-mcp-proxy@*
  • soma-mcp-server@*
  • soma-observability@*
  • soma-openapi@*
  • soma-provider-adapters@*
  • soma-provider-core@*
  • soma-tauri-shell@*
  • soma-api@*
  • soma-application@*
  • soma-cli@*
  • soma-client@*
  • soma-config@*
  • soma-domain@*
  • soma-integrations@*
  • soma-mcp@*
  • soma-palette@*
  • soma-runtime@*
  • soma-test-support@*
  • soma-web@*