Cdt Express Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Cdt Express Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Interact with climate metrics via Riskthinking.AI's CDT Express API in supported AI chat experiences.
This project contains:
cdt-express.mcpb file from the releases page.cdt-express.mcpb file.a. Alternatively, you can manually configure in "Settings" -> "Extensions", and configure the Tool permissions for this extension.
CDT Express Climate API:
v0.1.0: Climate exposure metricsv0.2.0: Climate impact metricsv0.2.0: Probability-adjusted impactv0.2.0: Climate exposure distributionv0.2.0: Climate impact distributionOther CDT Express APIs:
v0.3.0: Physical Assets APIv0.3.0: Companies APIv0.3.0: Markets APIIntegration:
v0.1.0: Support Stdio transport for local MCP server connectivity (e.g. extension for Claude desktop app and IDEs such as Cursor.)nvm use to use the version specified in .nvmrc.npm inpm run pack:dev. You should find the cdt-express.mcpb file in the root directory.npm run pack in that it installs back the development dependencies after packaging.package.json and src/server.ts (constant SERVER_VERSION), without the v prefix (e.g. 0.5.2 instead of v0.5.2.)v prefix (e.g. v0.5.2). Typically do this through a new GitHub Release https://github.com/RiskThinking/cdt-express-mcp/releases/new, which has the advantage of ensuring code integrity and avoid unexpected local commits/changes.server.jsonThe version, package[0].sha256, and package[0].identifier fields in server.json are automatically calculated and injected by the GitHub Actions workflow, therefore intentionally not kept in version control.
Please refer to https://github.com/modelcontextprotocol/registry for latest details on the MCP Registry and track potential changes to the process.
manifest.jsonThe version field in manifest.json is automatically synced with the version in package.json by the npm run sync-manifest command (invoked by npm run pack), therefore intentionally not kept in version control. If you intend to make any manifest.json changes other than version, you should make sure to commit the changes before running npm run pack as it would reset (by git checkout manifest.json) the whole file.
Please refer to https://github.com/modelcontextprotocol/mcpb/blob/main/MANIFEST.md for the latest MCPB manifest specification.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.