Server definition
- Hash
- sha256:d36b5e04703dd57a8708b390900ee06ae01f7ef060d1d25da122d6b72475cf16
- What it is
- What a remote MCP server returned when asked what it offers: 1 tools
The blob, as servednamed by its sha256
{
"instructions": "Scan a public GitHub MCP-server repo with compuute-scan, the MCP-specific static security scanner (38 L1 rules across TS/JS, Python, Go, Rust, C#, Java, Kotlin). Use this before an agent connects to an unknown MCP server or before installing a third-party MCP-server package. Every response carries a triage disclaimer: findings are pattern matches, not exploitability claims — manual dataflow review required for production decisions.",
"tools": [
{
"description": "Scan a public GitHub MCP-server repository for security issues.\n\n Clones the repo (shallow, <60s, <200 MB), runs compuute-scan v0.6.2 in\n static analysis mode (no code execution from the target), and returns a\n structured report with severity counts, a 0-100 score, and the 10 most\n severe findings.\n\n WHEN TO USE:\n - Before connecting to an unknown MCP server discovered via Anthropic\n Registry, Smithery, mcp.so, or a Discord recommendation.\n - Before installing a third-party MCP-server package into a production\n pipeline.\n - As part of an agent's pre-commit / pre-deploy due-diligence step\n when adding new dependencies.\n - As one input to a multi-source trust evaluation (combine with\n publisher reputation, package install count, last-update recency).\n\n WHEN NOT TO USE:\n - For private repos. Use the on-prem CLI instead:\n `npx compuute-scan ./path-to-private-repo`\n - For deep exploitability assessment of a specific code path. This is\n pattern matching, not dataflow analysis. Book a manual L2-L4 audit\n at https://compuute.se/audit for that depth.\n - For non-GitHub hosts (GitLab, Bitbucket, self-hosted). v1 supports\n github.com only.\n - For repos > 200 MB or clone time > 60s. The endpoint returns a 413\n or 504 in those cases — fall back to local CLI.\n\n EXPECTED RESPONSE TIME:\n - Median: ~1-2 seconds for small repos (<100 files).\n - p99: ~10 seconds for medium repos.\n - Hard timeout at clone=60s, scan=120s combined.\n\n EXPECTED COST:\n - Free tier in MVP. Future Pro tier may charge per-scan or per-month.\n\n DATA FRESHNESS:\n - Scanner version is reported in response.scanner.version.\n - L1 rule set freshness reflects compuute-scan releases — see\n github.com/Compuute/compuute-scan/CHANGELOG.md for the latest CVE\n and threat-intel response timeline.\n\n EXAMPLES:\n\n Example 1 — scan an MCP server you're evaluating:\n github_url = \"https://github.com/modelcontextprotocol/servers\"\n → score: 0, summary: {critical: 1, high: 94, medium: 22}\n → top_findings include SSRF, eval, etc.\n → recommendation: \"AVOID — 1 critical and 94 high finding(s)...\"\n\n Example 2 — scan a clean reference implementation:\n github_url = \"https://github.com/microsoft/azure-devops-mcp\"\n → score: 90+, summary: {critical: 0, high: 1}\n → recommendation: \"REVIEW — 1 high finding(s)...\"\n\n Example 3 — scan your own dev MCP-server before publishing:\n github_url = \"https://github.com/yourorg/your-mcp\"\n → audit your own surface before others install it\n\n OUTPUT FIELDS (stable schema):\n - repo_url (str): canonical URL of the scanned repo.\n - score (int): 0-100, higher safer. Coarse summary, not a precision claim.\n - summary (object): {critical, high, medium, low, info, files_scanned}.\n - recommendation (str): action guidance derived from severity counts.\n - findings_count (int): total raw findings (may include false positives).\n - top_findings (list): up to 10 most severe, each with {id, title,\n severity, file, line, owasp, cwe}.\n - l0_discovery (object): MCP transport, tool count, dependency pinning.\n - performance (object): clone_seconds, scan_seconds, repo_size_bytes.\n - scanner (object): {name, version, layers_covered}.\n - _disclaimer (str): MANDATORY triage disclaimer. Read it.\n\n Args:\n github_url: Public GitHub HTTPS URL (e.g. https://github.com/org/repo).\n Must be public and < 200 MB. v1 is github.com only.\n\n Returns:\n Structured scan result. On error, returns {\"error\": code, \"message\": ...}\n with HTTP-style code (invalid_url, clone_failed, scan_timeout, etc.).\n ",
"inputSchema": {
"properties": {
"github_url": {
"title": "Github Url",
"type": "string"
}
},
"required": [
"github_url"
],
"title": "scan_mcp_serverArguments",
"type": "object"
},
"name": "scan_mcp_server",
"outputSchema": null
}
]
}Verify it yourself
curl -s https://api.teppi.xyz/v1/evidence/sha256:d36b5e04703dd57a8708b390900ee06ae01f7ef060d1d25da122d6b72475cf16 | sha256sum