github TypeScript analyzed 7b928de

gaffer-sh/mcp

github

Gaffer MCP for storing and retrieving Test and CI Artifacts

maintainer
gaffer-sh
license
MIT
first seen
2026-08-08
last seen
2026-08-11
releases · 30d
3
short id

Drift inferred · capture-to-capture

No drift recorded — single capability capture; advisories appear once its surface changes.

capabilities 2 tools
transport stdio · http counts 2 tools · 0 res · 0 prompts permission surface via code analysis

tools

  • execute_code
  • search_tools
skills & danger signals github-tarball
prompt-surface shipped agent-instruction files + hidden-content / dangerous-code findings — quoted from the analyzed source

analyzed commit 7b928de · analyzer v33 · 3d ago

skills & prompt files 1

code evidence vmcp-v0.9.0 · github-tarball
evidence-backed findings quoted directly from the published source artifact — not inferred

code files: 37

filesystem 1

  • fs (weak) gaffer-sh-mcp-7b928de/src/codemode/__tests__/docs-sync.test.ts :1 import { readFileSync } from 'node:fs'

network 1

  • net gaffer-sh-mcp-7b928de/src/api-client.ts :182 const response = await fetch(url.toString(), {

secrets 3

  • secrets gaffer-sh-mcp-7b928de/src/api-client.ts :96 const apiKey = process.env.GAFFER_API_KEY
  • secrets (weak) gaffer-sh-mcp-7b928de/src/codemode/__tests__/executor.test.ts :11 ['process', 'process.env.SECRET'],
  • secrets gaffer-sh-mcp-7b928de/src/index.ts :68 const apiKey = process.env.GAFFER_API_KEY

tool registrations 2

  • execute_code gaffer-sh-mcp-7b928de/src/index.ts :141
  • search_tools gaffer-sh-mcp-7b928de/src/index.ts :227

declared dependencies 7

  • @modelcontextprotocol/sdk@^1.0.0
  • zod@^3.23.0
  • @types/node@^22.0.0
  • bumpp@^10.1.0
  • tsdown@^0.20.3
  • typescript@^5.7.2
  • vitest@^3.0.0