Scorezilla Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Scorezilla Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Official Model Context Protocol (MCP) server for Scorezilla — the easiest way to add a leaderboard to your game. Connect this server to your AI coding assistant (Claude Code, Cursor, Continue.dev, …) and ship a working leaderboard without leaving your editor.
Eleven tools total — five read-only, and six that write: four that create resources (bootstrap_leaderboard, create_game, create_board, mint_key) plus two that update config (update_board_config — score bounds + retention, e.g. an anti-cheat maxScore; update_game_config — the browser-submit origin allowlist).
Status — v0.3.0. Published on the@latestdist-tag.0.3.0adds three create-only write tools —create_game,create_board,mint_key— so an agent can provision against an existing game (add boards, mint keys, create more games), not just bootstrap a brand-new one.0.2.0added the integration-axis arguments (identity strategy, OAuth provider, hosting/anti-cheat pattern, server language) tobootstrap_leaderboard+get_sdk_snippet. Destructive ops (edit/delete, key revocation) remain dashboard-only by design.
Sign in at dashboard.scorezilla.dev, open MCP tokens, click Create token. Copy the mcp_live_* value once — it's not shown again.
Claude Code — edit ~/.claude/settings.json:
{
"mcpServers": {
"scorezilla": {
"command": "npx",
"args": ["-y", "@scorezilla/mcp"],
"env": {
"SCOREZILLA_TOKEN": "mcp_live_…"
}
}
}
}🔒 Keep `~/.claude/settings.json` private. The token is stored in plaintext in that file. Make sure it's not committed to git (it's usually in your.gitignore), not synced to a public dotfiles repo, and not backed up to a shared location. On macOS/Linux:chmod 600 ~/.claude/settings.jsonso only your user can read it. If a token leaks, revoke it at dashboard.scorezilla.dev/account/tokens.
Cursor — open Settings → Features → MCP → Add new MCP server, then use the same command + args + env shape.
Anything else MCP-compatible — point your client at npx -y @scorezilla/mcp with SCOREZILLA_TOKEN set in the environment.
In Claude Code or Cursor: _"Add a Scorezilla leaderboard to this game."_
| Tool | What it does |
|---|---|
list_games | Lists your games. Use this first to orient. |
list_boards | Lists leaderboards under a game. |
get_keys | Returns the public key (safe to embed) and the secret-key prefix. The full secret never leaves the dashboard. |
get_board_top_n | Returns the top entries on a board. The "is my integration working?" tool. |
get_sdk_snippet | Returns ready-to-paste integration code for a board. Optional axis args tailor it: anonymous/OAuth identity, client-only vs. server-validated anti-cheat, and the server language (TS/Python/Go/C#). |
bootstrap_leaderboard | Creates a new game + first board in one call, then returns the widget embed + SDK snippet + a plain-English recommendation. Same optional axis args (anti-cheat, OAuth, server language). The 90-second-demo path. |
create_game | Creates a new (empty) game. Use when a game already exists (so bootstrap_leaderboard would conflict) or you want another. |
create_board | Adds a leaderboard board to an existing game (by gameId), with full options (sortDir, scoreKind, retention, bounds). |
mint_key | Mints a fresh public/secret key pair for an existing game. The secret is shown once. |
scorezilla-mcp [--read-only] [--base-url=<url>] [--version] [--help]--read-only — refuse to register the write tools (bootstrap_leaderboard, create_game, create_board, mint_key, update_board_config, update_game_config). Use this on shared/CI configs to guarantee the AI can't create or change resources.--base-url=<url> — override the API origin. Defaults to https://api.scorezilla.dev. Useful for self-hosted or staging environments.SCOREZILLA_TOKEN — required. Bearer token issued at dashboard.scorezilla.dev/account/tokens.SCOREZILLA_BASE_URL — same as --base-url, but via env. CLI flag wins if both are set.SCOREZILLA_BETA_TOKEN — pre-public closed-beta only. When set, sent as the X-MCP-Beta header on every API call to unlock the MCP namespace before the public switch is flipped. You'll only need this if a Scorezilla team member gave you a beta token; ignore otherwise.env blocks, password managers, or secret stores.https://api.scorezilla.devReleases are CI-driven and require an approval click in the npm-publish GitHub Environment. The full flow:
pnpm changeset — describes what changed and the bump type. Commit the file under .changeset/..github/workflows/release.yml runs and opens a "chore(release): version @scorezilla/mcp" PR that bumps package.json, syncs server.json (the MCP Registry manifest) via scripts/sync-server-json-version.mjs, and updates CHANGELOG.md.--provenance (verifiable build attestation via GH OIDC + sigstore)mcp-publisher login github-oidc → mcp-publisher publishnode dist/index.js --version), and release:check (asserts package.json and server.json versions agree).Manual publishes from a developer terminal still work (bash scripts/publish.sh) but aren't the path CI takes — they skip provenance and approval gates. Use only for one-off recovery.
MIT.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.