Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Mcp (Agent Skill) and scored it 45/100 (orange). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 1 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
A base64 string of 128+ characters appears in a documentation file. Encoded prompt injection hides the hostile instruction in base64 — invisible to keyword filters — and relies on the agent's ability to decode it at runtime. There is no normal authoring reason to embed a multi-hundred-byte base64 blob in skill docs.
*.sig, SIGNATURES) outside the documentation.Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
An MCP (Model Context Protocol) server that lets AI agents query a Fangorn subgraph schemas and conformant data published by data sources.
pnpm i
cp env.example .env
# Edit .env and set SUBGRAPH_URL and SUBGRAPH_API_KEY (if calling published Subgraph)
pnpm buildTo build the docker image, run:
docker build -f Dockerfile \
-t us-central1-docker.pkg.dev/lucky-lead-489114-d7/fangorn-network/mcp:latest .where the tag is your desired registry/namesepace, e.g. for the GCP docker image registry us-central1-docker.pkg.dev/lucky-lead-489114-d7
pnpm start
# or
TRANSPORT=stdio node build/index.jsTRANSPORT=http PORT=4000 node build/index.js
# Server listens at http://localhost:4000/mcpAfter configuring .env, from the root run:
docker compose upWhen running in HTTP mode, clients connect to http://localhost:4000/mcp using the Streamable HTTP transport.
Use the MCP Inspector to test tools interactively:
pnpm inspect~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.