Scan identity
Evidence summary
This is the official visual testing tool for MCP servers. The bounded review observed a root MCP configuration pointing at MCP documentation, extensive validation/build automation and explicit Model Context Protocol v2 client/server dependencies.
Evidence categories
MCP configuration
FoundSelected configuration evidence was observed. This does not establish how any user's client is configured.
.mcp.jsonmcpServers entry points to the official MCP documentation HTTP endpoint
Shell / command execution
Not establishedNo shell/command execution claim is made from the selected bounded evidence.
CI/CD automation
FoundRepository automation and validation tooling are present in the selected scope.
.github/GitHub automation directory observedpackage.jsonvalidation, coverage, build-gate and smoke-test scripts declared
Supply-chain / dependencies
FoundSelected package dependency declarations were observed; this is not a complete dependency audit.
package.json@modelcontextprotocol/client, core, server and server-legacy 2.0.0 dependencies declared
Scope and limitations
Scan mode: BOUNDED_ROOT_AND_SELECTED_DEPTH1_PLUS_TARGETED_SEARCH. General recursive crawl: NO.
- Public, selected and bounded repository evidence only.
- FOUND means evidence observed, not risk or malicious behavior proven.
- Evidence was reviewed against immutable commit 1e31c78fbf81a989e8eb47021c6281d7876ad7fd.
- No repository clone or target-code execution.
- No secret/token values are included.
- No CVE or package-reputation lookup.
- No numeric security score and no safe/unsafe verdict.
Repository context
Trust/community metadata is descriptive context only; it is not a security guarantee.