Scan identity
Evidence summary
This repository is directly relevant to MCP implementers and has strong qualified-search potential. The bounded review observed MCP configuration examples in multiple server READMEs, child-process use in filesystem tests, workspace dependency declarations and repository automation.
Evidence categories
MCP configuration
FoundSelected configuration evidence was observed. This does not establish how any user's client is configured.
src/fetch/README.mdmcpServers configuration examplesrc/git/README.mdgit server configuration examplesrc/memory/README.mdmemory server configuration example
Shell / command execution
FoundSelected process-spawn evidence was observed in tests. This does not prove a vulnerability or malicious behavior.
src/filesystem/__tests__/startup-validation.test.tsspawn imported from child_processsrc/filesystem/__tests__/structured-content.test.tschild_process spawn used in server test flow
CI/CD automation
FoundRepository automation is present in the bounded root scope.
.github/GitHub automation/configuration directory
Supply-chain / dependencies
FoundRoot workspace dependencies were observed; this is selected evidence rather than a complete dependency audit.
package.jsonnpm workspaces with four @modelcontextprotocol server dependencies and dependency overrides
Scope and limitations
Scan mode: BOUNDED_ROOT_AND_SELECTED_DEPTH1_PLUS_TARGETED_SEARCH. General recursive crawl: NO.
- Public, selected and bounded repository evidence only.
- FOUND means evidence observed, not risk or malicious behavior proven.
- Search matches were reviewed against immutable commit f46d9578190b476b3501923ea8977d899e8db2cb.
- No repository clone or target-code execution.
- No raw secret/token values are included.
- No CVE or package-reputation lookup.
- No numeric security score and no safe/unsafe verdict.
Repository context
Trust/community metadata is descriptive context only; it is not a security guarantee.