SaferSkills independently audited MCPbundler (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
<h1 align="center">MCP Bundler (macOS)</h1>
MCP Bundler is a macOS SwiftUI app for managing and running Agent Skills and Model Context Protocol (MCP) servers, with a headless stdio mode for CLI and automation workflows. The codebase targets the MCP lifecycle spec baseline dated 2025-06-18.
I decided to move the project from Paid software to open source thanks to <a href="https://bags.fm/">Bags platform</a> I need some time to prepare the code for open sourcing it and for allowing to download builds straight from the site and remove license gate. Bear with me, I need some hours for this.
Until then you can download app here: <a href="https://mcp-bundler.com/downloads/MCPBundler-latest.zip">TEMP DOWNLOAD LINK</a>
MCP Servers view _Servers list with folders, health status, and quick actions._
Skills library _Skills library with folders and per-location toggles._
Project settings _Project settings for skill sync locations, marketplaces, and optimizations._
Project logs _Project logs with auto-refresh controls and pagination._
Skills marketplace _Skills marketplace browser with categories and install actions._
PRs should describe changes, list tests run, and link relevant spec sections or issues.
Be respectful and constructive. By participating, you agree to follow the GitHub Community Guidelines.
Please use GitHub Security Advisories for sensitive disclosures. Do not file public issues for security vulnerabilities.
Open a GitHub issue with clear steps to reproduce, logs, and screenshots where relevant.
Apache-2.0. See LICENSE.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.