Mmcp.market

security-preflight

by jdhart81·io.github.jdhart81/security-preflight·v1.3.1

Static MCP, source-code and injection-indicator checks with redacted signed receipts.

B81/100grade B
What users say
No reviews yet
Be the first
Safety scan
B81/100

full report

Adoption
Not measured yet

Usage numbers are collected on the next scan

Reviews

Write one

Nobody has reviewed security-preflight yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

Tools (5, 1 write)

write = sends, deletes, buys or posts
  • describe_agentFree

    Describe scope, evidence boundary, inputs, and outputs.

  • get_security_receiptFree

    Read a previously issued public, input-redacted receipt.

  • scan_sourceFree

    $1 bounded inline VulnCanon source scan; indicators, not proven exploits. At most 64 KiB, 2000 lines, 4096 characters per line. No model calls, repository fetching or code execution. Returns a redacted signed receipt.

  • screen_injectionFree

    $1 batch of 1–20 text samples screened for deterministic injection markers. Maximum 64 KiB total. Heuristic indicators, not calibrated probabilities or a guarantee of safety. No model calls or automatic follow-on purchase.

  • security_preflightwrite actionFree

    Run a $1 static Security Preflight and return a signed receipt. New x402 payer wallets may receive the fleet-wide $0.01 introductory call. No deployed endpoint is fetched or tested. Importing the receipt into an Agent Market profile is a separate, explicit action.

Public scan report

scanner v0.1.2 · 2026-09-18 · same rubric, same numbers if you re-run it

1 high
  • Code scanremote-only server, no package to scann/a
  • Live reliabilityremote reachable in 1816ms20/20
  • Tool poisoning5 tool descriptions checked15/15
  • Auth qualityopen endpoint exposes 1 write-action tools with no auth3/15
  • Maintenancelast push 0 days ago15/15
  • Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10

Findings (1)

  • highWrite-action tools reachable without authenticationauth.open-write
Overall 81/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Install directly

claude mcp add --transport http security-preflight https://mcp.viridis-security.com/security-preflight/mcp
Add to Cursor

Alternatives to security-preflight

Same job, ranked by rating then adoption.

See all →
  • Draugr
    Security scanning for AI agents: SAST, SCA, secrets, IaC, DAST, ranked by real risk.
    A
  • Trooth
    Look up a witnessed Trust Profile, read a domain's security surface, or verify a Trust Ledger Token.
    A
  • b/cited
    AEO tools: scan any URL for AI-citation readiness, read the public leaderboard and citation panel.
    B
  • FlowSentry
    Security scanner for n8n workflows + live MCP Trust-Check. 18 rules, OWASP mapped. Paid x402 API.
    C