Scan identity
Evidence summary
No MCP configuration evidence was observed in the selected bounded scan. Observed evidence classes: Shell / command execution, Download / install, Agent permissions / behavior, CI/CD automation, Supply-chain / dependencies. Evidence observations are review signals, not a safe/unsafe verdict.
Evidence categories
Shell / command execution
FoundSelected evidence was observed. This does not prove a vulnerability, malicious behavior or unsafe operation.
README.mdsudopackage.jsonpowershell
Download / install
FoundSelected evidence was observed. This does not prove a vulnerability, malicious behavior or unsafe operation.
README.mdcurl, npm install, pnpm, yarn.github/workflows/containers.ymldocker.github/workflows/docs-locale-sync.ymlcurl.github/workflows/duplicate-issues.ymlcurlpackage.jsoninstall lifecycle: postinstall, prepare
MCP configuration
Not found in scanned scopeNo matching evidence was observed in the selected bounded scan scope. This is not proof of absence elsewhere.
Agent permissions / behavior
FoundSelected evidence was observed. This does not prove a vulnerability, malicious behavior or unsafe operation.
AGENTS.mdagent instruction/config file · tools / permissions, agent instructions, model config.github/workflows/close-issues.ymltools / permissions.github/workflows/close-prs.ymltools / permissions.github/workflows/compliance-close.ymltools / permissions, agent instructions.github/workflows/containers.ymltools / permissions.github/workflows/deploy.ymltools / permissions.github/workflows/docs-locale-sync.ymltools / permissions, agent instructions, model config.github/workflows/docs-update.ymltools / permissions, agent instructions, model config.github/workflows/duplicate-issues.ymltools / permissions, agent instructions.github/workflows/generate.ymltools / permissions.github/workflows/nix-eval.ymltools / permissions
CI/CD automation
FoundSelected evidence was observed. This does not prove a vulnerability, malicious behavior or unsafe operation.
.github/workflows/close-issues.ymlGitHub Actions workflow.github/workflows/close-prs.ymlGitHub Actions workflow.github/workflows/compliance-close.ymlGitHub Actions workflow.github/workflows/containers.ymlGitHub Actions workflow.github/workflows/deploy.ymlGitHub Actions workflow.github/workflows/docs-locale-sync.ymlGitHub Actions workflow.github/workflows/docs-update.ymlGitHub Actions workflow.github/workflows/duplicate-issues.ymlGitHub Actions workflow.github/workflows/generate.ymlGitHub Actions workflow.github/workflows/nix-eval.ymlGitHub Actions workflow.github/workflows26 direct workflow files
Supply-chain / dependencies
FoundSelected evidence was observed. This does not prove a vulnerability, malicious behavior or unsafe operation.
package.jsonparsed package manifest · 18 declared dependency entries
Scope and limitations
Scan mode: BOUNDED_ROOT_AND_SELECTED_DEPTH1. General recursive crawl: NO.
- Public, selected and bounded repository evidence only.
- FOUND means evidence observed, not risk or malicious behavior proven.
- NOT_FOUND_IN_SCANNED_SCOPE is not proof of absence outside the bounded scan.
- Trust/community metadata is descriptive context, not a security guarantee.
- Zero selected dependency evidence does not mean zero dependencies.
- No repository clone or target-code execution.
- No raw source-file bodies or secret/token values are included in this report.
- No general recursive crawl.
- No CVE lookup, package reputation lookup or package registry lookup.
- No numeric security score and no safe/unsafe verdict.
Repository context
Trust/community metadata is descriptive context only; it is not a security guarantee.