Grace Hello Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Grace Hello Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A very simple remote MCP server (Streamable HTTP transport) that advertises a custom icon per the MCP spec (rev 2025-11-25, SEP-973), ready to deploy on Render.
It exposes one tool, say_hello, and serves a custom PNG icon that is advertised in the initialize response's serverInfo.icons.
| File | Purpose |
|---|---|
server.js | The MCP server (Express + @modelcontextprotocol/sdk, Streamable HTTP). |
make_icon.py | Generates static/icon.png (stdlib only, no deps). Edit to change the icon. |
static/icon.png | The icon that gets advertised + served. |
render.yaml | Render blueprint for one-click deploy. |
npm install
npm start # serves on http://localhost:3000http://localhost:3000/mcpQuick smoke test:
curl -s -X POST http://localhost:3000/mcp \
-H 'Content-Type: application/json' \
-H 'Accept: application/json, text/event-stream' \
-d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-11-25","capabilities":{},"clientInfo":{"name":"curl","version":"0"}}}'You should see serverInfo.icons in the response.
Or use the official MCP Inspector (renders the icon):
npx @modelcontextprotocol/inspector
# then connect to http://localhost:3000/mcp (Streamable HTTP)render.yamland creates a free Node web service. (Or New ➜ Web Service manually: build npm install, start npm start.)
RENDER_EXTERNAL_URL automatically, so server.js builds thecorrect absolute https://<your-service>.onrender.com/icon.png icon URL — no manual env vars needed.
https://<your-service>.onrender.com/mcp.Note: Render's free plan sleeps on idle, so the first request after a while may take ~30s to wake.
Claude Code (CLI):
claude mcp add --transport http grace-hello https://<your-service>.onrender.com/mcpThen in a session: /mcp to see it, and ask Claude to "use say_hello to greet Rajith".
Claude Desktop / other GUI clients: add a remote/HTTP MCP server pointing at https://<your-service>.onrender.com/mcp.
This server advertises its icon correctly per the MCP spec: the icons array appears on serverInfo (and on the tool). It must be an https:// or data: URI — we use the hosted https://.../icon.png.
Whether a client shows it is up to that client. Icon rendering is a newer, inconsistently-supported feature:
placeholder for arbitrary third-party servers — the branded icons in Claude's marketplace are first-party integrations configured on Anthropic's side. As client icon support matures, this server is already compliant and will "just work" with no changes.
make_icon.py, then npm run make-icon(regenerates static/icon.png). Or just drop your own 512×512 PNG at static/icon.png.
setRequestHandler cases / tool definitions in server.js.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.