Mmcp.market

Penholder MCP server

by penholder.ai·ai.penholder/penholder·v1.0.0

Preventive human-approval write-gate for AI agents: writes commit only after a human approves.

C62/100grade C
What users say
No reviews yet
Be the first
Safety scan
C62/100

full report

Adoption
New

Little public usage data yet

Reviews

Write one

Nobody has reviewed Penholder yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

Penholder tools

Tool list not cached yet. `describe` through the gateway fetches it live.

Public scan report

scanner v0.1.9 · 2026-09-23 · same rubric, same numbers if you re-run it

1 low
  • Code scanremote-only server, no package to scann/a
  • Live reliabilityremote reachable in 334ms; handshake note: MCP error -32001: invalid api key20/20
  • Tool poisoningtools not inspected (endpoint requires auth); not countedn/a
  • Auth qualityopen endpoint, read-only tools10/15
  • Maintenanceno repository listed3/15
  • Maintainer identityverified namespace with website, no repo4/10

Findings (1)

  • lowNo source repository listedmaint.no-repo
Overall 62/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Install directly

claude mcp add --transport http penholder https://api.penholder.ai/mcp
Add to Cursor

Penholder: common questions

Is Penholder MCP server safe?
With care: it is graded C, so read the findings first (62/100). Read the Penholder safety report
How do I install Penholder?
It runs remotely at api.penholder.ai. Add it to Claude Code, Claude Desktop or Cursor with the snippets above, or call it through the mcp.market gateway without installing anything.
Does Penholder need an API key?
Not as far as the registry entry and our scan can tell: no credentials are declared or required.
Is Penholder maintained?
The latest release is v1.0.0.
Is Penholder up?
100% of our last 20 checks got an answer. We check remote servers about four times a day.

More from penholder.ai