Ai — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Ai (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
This repo is your public entry point for Brivvy AI integrations. You get MCP server metadata, install steps, client connection profiles, and release notes.
The implementation stays private. Everything here is safe to publish.
https://mcp.brivvy.io.https://mcp.brivvy.io/.well-known/oauth-protected-resource.https://mcp.brivvy.io/.well-known/oauth-authorization-server.These tool names are the public contract. Short descriptions match what the hosted server exposes today (see MCP Server for connection guides, security notes, and FAQs).
| Area | Tool | What it does |
|---|---|---|
| Voices | list_voices | Lists published voices in your workspace. |
| Voices | get_voice | Returns tone and style rules for the default or a chosen voice. |
| Templates | list_templates | Lists content templates saved in your workspace. |
| Templates | list_discover_templates | Lists public templates from the Brivvy community catalog. |
| Templates | get_template | Returns the full prompt and instructions for a template you select. |
Add Brivvy as a remote MCP server:
{
"mcpServers": {
"Brivvy": {
"url": "https://mcp.brivvy.io"
}
}
}Connect once, then finish OAuth in the browser when the client asks you to.
Point your MCP connector at:
https://mcp.brivvy.io.Claude reads .well-known metadata and walks you through consent.
Your Brivvy account uses one workspace at a time for MCP. The workspace you last picked on the OAuth screen applies to every MCP client until you authorize again and choose a different one. If you run Cursor and Claude side by side, they do not keep separate workspace picks today.
Your access token stays short-lived. The client should refresh it with your refresh token. Refresh tokens last 90 days (Amazon Cognito). When that window ends, connect again and run through OAuth.
WWW-Authenticate hint and complete discovery.mcp/server.json, registry metadata.mcp/install/, Cursor and Claude profiles.VERSIONING.md, how we version this public metadata.CHANGELOG.md, release notes.SECURITY.md, how to report issues.Internal release and directory workflows stay in the private Brivvy MCP repo.
[email protected].[email protected].~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.