Universal AI Development Platform with working MCP integration, multi-provider support, voice (TTS/STT/realtime), and professional CLI. 58+ external MCP servers discoverable, multimodal file processing, RAG pipelines. Build, test, and deploy AI applicatio
- capability exposureinferred+35
- recent driftinferred+12
- inherited (deps)attested+15
- tool safetyinferred+24
- trust mitigatorsmixed−14
attestedinferredmixed
The A–E grade is our heuristic synthesis — a "review this" prompt, not a verdict. Each factor is tagged by what backs it: attested (a verifiable record), reported (a third party's claim), or inferred (our own heuristic, e.g. permissions). See methodology.
graded 15m ago · see ecosystem CVEs →
No known CVEs for this server.
inherited (deps) · grade factor +15
- highdangerous code
dynamic exec: new Function()
- mediumtool shadowingreadFile
tool "readFile" shadows a verified server's tool
- mediumtool shadowingwriteFile
tool "writeFile" shadows a verified server's tool
- lowexfiltration combo
sensitive read and network capabilities split across this server's tools
analyzed v9.71.0 · analyzer v18 · 10h ago
danger signals10
- dynamic code executionnew Function()package/dist/agent/directTools.js:200
const result = new Function(`'use strict'; return (${expression})`)(); - dynamic code executionnew Function()package/dist/lib/agent/directTools.js:200
const result = new Function(`'use strict'; return (${expression})`)(); - dynamic code executionnew Function()package/dist/lib/utils/schemaConversion.js:462
const createZodSchema = new Function("z", `return ${schemaExpression}`); - dynamic code executionnew Function()package/dist/utils/schemaConversion.js:462
const createZodSchema = new Function("z", `return ${schemaExpression}`); - over-broad OAuth scopehttps://www.googleapis.com/auth/cloud-platformpackage/dist/adapters/video/vertexVideoHandler.js:157
scopes: ["https://www.googleapis.com/auth/cloud-platform"], - over-broad OAuth scopehttps://www.googleapis.com/auth/cloud-platformpackage/dist/lib/adapters/video/vertexVideoHandler.js:157
scopes: ["https://www.googleapis.com/auth/cloud-platform"], - over-broad OAuth scopehttps://www.googleapis.com/auth/cloud-platformpackage/dist/lib/providers/googleVertex.js:4487
scopes: ["https://www.googleapis.com/auth/cloud-platform"], - over-broad OAuth scopehttps://www.googleapis.com/auth/cloud-platformpackage/dist/lib/voice/providers/GoogleSTT.js:432
scopes: ["https://www.googleapis.com/auth/cloud-platform"], - over-broad OAuth scopehttps://www.googleapis.com/auth/cloud-platformpackage/dist/providers/googleVertex.js:4487
scopes: ["https://www.googleapis.com/auth/cloud-platform"], - over-broad OAuth scopehttps://www.googleapis.com/auth/cloud-platformpackage/dist/voice/providers/GoogleSTT.js:432
scopes: ["https://www.googleapis.com/auth/cloud-platform"],
- recent drift+12 capability drift →
Heuristic, inferred signals — false positives (legitimately powerful tools, forks, language ports) are expected. Treat each as "review this", not a verdict. See the ecosystem-wide picture on the security hub, or the fleet security of balaganesh_juspay.