Drive an MCP server over real stdio against a real backend, and prove every tool was exercised
Drift inferred · capture-to-capture
No drift recorded — single capability capture; advisories appear once its surface changes.
transport — counts 0 tools · 0 res
· 0 prompts
permission surface via code analysis
No tools enumerated yet for this server.
prompt-surface
shipped agent-instruction files + hidden-content / dangerous-code findings —
quoted from the analyzed source
analyzed commit 0b2cd15 · analyzer v33 · 1w ago
danger signals1
- suspicious endpoint 169.254.169.254 (cloud metadata) ni-c-mcp-integration-harness-0b2cd15/test/loopback.test.ts :33
'http://169.254.169.254/latest/meta-data/',
evidence-backed
findings quoted directly from the published source artifact — not inferred
code files: 11
network 2
- net ni-c-mcp-integration-harness-0b2cd15/src/wait.ts :1
import { createConnection } from 'node:net'; - net (weak) ni-c-mcp-integration-harness-0b2cd15/test/wait.test.ts :1
import { createServer, type Server } from 'node:http';
install hooks 1
- prepublishOnly ni-c-mcp-integration-harness-0b2cd15/package.json :45
npm run build
declared dependencies 12
- @modelcontextprotocol/client@^2.0.0
- @modelcontextprotocol/core@^2.0.0
- @modelcontextprotocol/server@^2.0.0
- mcp-internal-hosts@^0.2.0
- @types/node@^26.2.0
- @vitest/coverage-v8@^4.1.10
- mcp-approval@^0.7.0
- oxlint@^1.80.0
- prettier@^3.6.0
- typescript@^7.0.2
- vitest@^4.1.10
- zod@^4.4.3