Mechanic Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Mechanic Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Mechanic MCP server for the task library and docs. Built for writing and customizing Mechanic tasks (Shopify automation app: https://apps.shopify.com/mechanic). Offline by default (bundled data), serving public URLs for tasks (https://tasks.mechanic.dev) and docs (https://learn.mechanic.dev).
npx @lightward/mechanic-mcp@latest): {
"mcpServers": {
"mechanic-mcp": {
"command": "npx",
"args": ["-y", "@lightward/mechanic-mcp@latest"]
}
}
} {
"mcpServers": {
"mechanic-mcp": {
"command": "npx",
"args": ["-y", "@lightward/mechanic-mcp@latest"]
}
}
}~/.codex/config.toml): [mcp_servers.mechanic-mcp]
command = "npx"
args = ["-y", "@lightward/mechanic-mcp@latest"]search_tasks: returns public URL, tags, subscriptions/subscriptions_template, options.search_docs: returns public URL/sourceUrl.get_task (tasks only): script + subscriptions + options + JS blocks; not full JSON.get_doc (docs only): full markdown.similar_tasks: related tasks by tags/subscriptions/title.refresh_index: rebuild (not needed for packaged data).dist/data/index.json.gz, records.json.gz, manifest.json (users don’t need source repos). MECHANIC_DOCS_PATH=/path/to/mechanic-docs MECHANIC_TASKS_PATH=/path/to/mechanic-tasks npm run build:data
npm run buildnpm run test:smoke, npm run test:smoke-doc, npm run test:smoke-task.npm publish (use --access public for scoped packages).MECHANIC_DATA_PATH (default dist/data), MECHANIC_DOCS_PATH, MECHANIC_TASKS_PATH, repo URLs/branches, sync interval.MECHANIC_DATA_PATH; refresh_index rebuilds if you opt in. Stdio transport; TF-IDF search with fuzzy + pagination; no network calls for search/resources.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.