Direxio Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Direxio Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Local MCP server for Direxio chat workflows.
npm install -g @direxio/local-mcpFor local testing before publishing the package:
npm install -g /home/adam/direxio/direxio-mcpSet:
export DIREXIO_DOMAIN="https://example.com"
export DIREXIO_AGENT_TOKEN="<agent token>"DIREXIO_DOMAIN must be the service origin. Do not include /_p2p or /_matrix.
The server uses only DIREXIO_AGENT_TOKEN. It does not request, store, or expose Matrix access tokens.
direxio-mcpExample MCP client configuration:
{
"mcpServers": {
"direxio": {
"command": "direxio-mcp",
"env": {
"DIREXIO_DOMAIN": "https://example.com",
"DIREXIO_AGENT_TOKEN": "<agent token>"
}
}
}
}search_rooms - search or list contacts, groups, and channels.send_message - send a plain text ordinary message by room_id.list_messages - read ordinary messages by room_id and optional from_ts / to_ts.list_channel_posts - read channel posts by channel room_id.list_post_comments - read comments for a channel post_id.comment_channel_post - publish a plain text comment to an existing channel post.All tool results are concise JSON text.
If Node.js is not on PATH in WSL/Linux, use a reusable user-local install:
export PATH="/home/adam/.local/node/bin:$PATH"Then run:
npm test
npm run typecheck
npm run build
npm pack --dry-runThe normal unit suite does not require a Direxio backend:
npm testAfter the backend implements the six mcp.* actions, run the local Docker e2e harness with:
export DIREXIO_E2E=1
export DIREXIO_DOMAIN="https://localhost:8448"
export DIREXIO_AGENT_TOKEN="<agent token>"
npm run test:e2e:localFor self-signed local Docker certificates, run with NODE_TLS_REJECT_UNAUTHORIZED=0.
With only DIREXIO_DOMAIN and DIREXIO_AGENT_TOKEN, the e2e suite smoke-tests search_rooms. Set these optional fixture IDs to exercise the remaining tools:
export DIREXIO_E2E_ROOM_ID="!room:dendrite-a:8448"
export DIREXIO_E2E_CHANNEL_ROOM_ID="!channel:dendrite-a:8448"
export DIREXIO_E2E_POST_ID="post_123"DIREXIO_E2E_ROOM_ID enables send_message and list_messages. DIREXIO_E2E_CHANNEL_ROOM_ID enables list_channel_posts. DIREXIO_E2E_POST_ID enables list_post_comments and comment_channel_post.
The initial plan referenced @modelcontextprotocol/server. npm currently publishes that package only as 2.0.0-alpha.2. This package uses the stable official @modelcontextprotocol/sdk package instead, with imports from @modelcontextprotocol/sdk/server/mcp.js and @modelcontextprotocol/sdk/server/stdio.js.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.