Gaffer MCP for storing and retrieving Test and CI Artifacts
Drift inferred · capture-to-capture
No drift recorded — single capability capture; advisories appear once its surface changes.
transport stdio · http counts 2 tools · 0 res
· 0 prompts
permission surface via code analysis
tools
-
execute_code
-
search_tools
prompt-surface
shipped agent-instruction files + hidden-content / dangerous-code findings —
quoted from the analyzed source
analyzed commit 7b928de · analyzer v33 · 3d ago
skills & prompt files 1
- agent-rules gaffer-sh-mcp-7b928de/AGENTS.md
evidence-backed
findings quoted directly from the published source artifact — not inferred
code files: 37
filesystem 1
- fs (weak) gaffer-sh-mcp-7b928de/src/codemode/__tests__/docs-sync.test.ts :1
import { readFileSync } from 'node:fs'
network 1
- net gaffer-sh-mcp-7b928de/src/api-client.ts :182
const response = await fetch(url.toString(), {
secrets 3
- secrets gaffer-sh-mcp-7b928de/src/api-client.ts :96
const apiKey = process.env.GAFFER_API_KEY - secrets (weak) gaffer-sh-mcp-7b928de/src/codemode/__tests__/executor.test.ts :11
['process', 'process.env.SECRET'], - secrets gaffer-sh-mcp-7b928de/src/index.ts :68
const apiKey = process.env.GAFFER_API_KEY
tool registrations 2
- execute_code gaffer-sh-mcp-7b928de/src/index.ts :141
- search_tools gaffer-sh-mcp-7b928de/src/index.ts :227
declared dependencies 7
- @modelcontextprotocol/sdk@^1.0.0
- zod@^3.23.0
- @types/node@^22.0.0
- bumpp@^10.1.0
- tsdown@^0.20.3
- typescript@^5.7.2
- vitest@^3.0.0