claude-code — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited claude-code (MCP Server) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
MCP server for the m-dev-tools org catalog. Exposes three first-class agent tools:
"parse JSON in M" → module:m-stdlib#STDJSON)AGENTS.md URL, verification commands, …)The server reads the catalog at <https://github.com/m-dev-tools/.github> over the network at call time; it is a thin wrapper, not a cache. See AGENTS.md for the contract and the AI users guide for the full walk-through.
<!-- Required by registry.modelcontextprotocol.io for PyPI ownership validation. Do not remove. --> mcp-name: io.github.m-dev-tools/m-dev-tools-mcp
pip install m-dev-tools-mcp
# or:
uvx m-dev-tools-mcp
# or from a GitHub Release wheel:
pip install https://github.com/m-dev-tools/m-dev-tools-mcp/releases/download/v0.2.4/m_dev_tools_mcp-0.2.4-py3-none-any.whlPoint any MCP client at the m-dev-tools-mcp binary the install provides:
{
"mcpServers": {
"m-dev-tools": { "command": "m-dev-tools-mcp" }
}
}Or for clients that consult the public MCP registry:
io.github.m-dev-tools/m-dev-tools-mcpmake install # creates .venv and installs editable + dev deps
make test # pytest
make check # lint + mypy + test + check-manifest + check-agents
make build # → wheel-out/m_dev_tools_mcp-<ver>-py3-none-any.whldocs/ai-discoverability/AI-discoverability-architecture.mddocs/ai-discoverability/phases/vX.Y.Z on main → .github/workflows/release.yml builds the wheel, attaches it to a GitHub Release, publishes to PyPI via Trusted Publisher OIDC, and updates the MCP registry record via GitHub OIDC.AGPL-3.0. Same license as every other m-dev-tools repo.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.