build-mcp-server — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited build-mcp-server (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Repo level instructions have precedence over this generic skill.
import { McpServer } from "@modelcontextprotocol/sdk/server/mcp.js";
import { StdioServerTransport } from "@modelcontextprotocol/sdk/server/stdio.js";
const server = new McpServer({
name: "md-vision",
version: "0.1.0",
});
// server.tool(...) or server.registerTool(...) — match whichever API the installed SDK exposes
async function main(): Promise<void> {
const transport = new StdioServerTransport();
await server.connect(transport);
}
main().catch((err) => {
console.error(err);
process.exit(1);
});stdio rules:
bin in package.json points at ./dist/server.js; run npm run build before testing.→ See references/tool-design.md for description and schema guidance.
Restrict paths and domains via CLI flags. Block filesystem and network access by default if no flags are provided. MCP Roots is deprecated in the next MCP standard — do not use it here.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.