npm JavaScript analyzed 0.6.0

@tickory/mcp

v0.6.0
npm

Tickory MCP server wrapper for saved scans, ad hoc scan execution, and relay routing

maintainer
tickoryapp
licence
MIT
first seen
2026-08-14
last seen
2026-08-14
releases · 30d
0
short id

@tickory/mcp is an MCP server distributed on npm, maintained by tickoryapp, tracked here since August 2026. It has shipped 5 releases (currently 0.6.0) and exposes 16 tools. Tools include tickory_add_relay_route, tickory_create_relay_source, tickory_create_scan, tickory_describe_indicators, tickory_explain_alert_event, tickory_get_alert_event, and 10 more. Its composite risk grade is A — an inferred review prompt computed from observed signals, not a verdict.

what we found

Reading the source raised one review prompt — exfiltration combo — each a pattern worth a human look rather than a finding of fault.

Its 16 tools appear to reach network and secrets, inferred from tool names, descriptions and input schemas rather than from observed behaviour.

full security breakdown →
tools 16
  • tickory_add_relay_route Add one direct relay route to telegram, webhook, discord, or email
  • tickory_create_relay_source Create a TradingView relay source and return the paste-ready TradingView setup payload
  • tickory_create_scan Create a new scan with CEL expression and hard gates
  • tickory_describe_indicators Describe available CEL variables, recommended guards, and example expressions
  • tickory_explain_alert_event Explain why an alert triggered or was suppressed
  • tickory_get_alert_event Fetch one alert event by UUID
  • tickory_get_relay_trace Fetch the full lifecycle trace for one relay source event
  • tickory_get_scan Fetch one scan by ID
  • tickory_list_alert_events List alert events with cursor pagination
  • tickory_list_relay_events List recent inbound relay events for one TradingView source
  • tickory_list_relay_sources List TradingView relay sources and direct-route summaries
  • tickory_list_scans List scans visible to the API key owner
  • tickory_replay_relay_event Replay one failed relay route when the backend allows it
  • tickory_run_ad_hoc_scan Execute a one-off expression immediately without creating a saved scan
  • tickory_run_scan Trigger a scan run immediately
  • tickory_update_scan Replace an existing scan definition
release cadence · 90d 0 releases

No releases yet.

recent releases last 5
version date src
0.6.0 2026-05-01 npm
0.3.0 2026-03-15 npm
0.2.1 2026-03-14 npm
0.2.0 2026-03-13 npm
0.0.0 2026-03-12 npm

view all →