py — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited py (MCP Server) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
<img width="960" height="540" alt="hero" src="https://github.com/user-attachments/assets/094c8e05-b2de-4213-952f-c5542ccb354a" />
For more info, check out the blog post here or here: https://johnlarkin1.github.io/2025/larkin-mcp/
Slight lie with the photo though is that the Typescript version is that I did scope that one.... so it's actually bunx @johnlarkin1/larkin-mcp rather than just bunx larkin-mcp. I talk about why I did this in the blog.
This is going to be a MCP connector that runs it's tools locally over stdio and makes no external connections. The goal is that you'll be able to download it, use Claude Desktop / ChatGPT / Claude Code and integrate and ask questions.... about me. So a smidge egotistical I suppose, but I want to get some more reps in with doing this.
Alrighty so this is largely going to be for me and because I'm getting sick of how much I'm using all the AI tooling, so want to make sure I still flex the skills. I'm gonna be disabling Cursor for the entirety of this repo.
I want to have the same MCP server across Python, Typescript, and Rust. so you can check out the various subdirs. uv and cargo and bun given Anthropic's recent acquisition I feel like I might as well use it.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.