Tomcat Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Tomcat Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A local Tomcat management MCP server for Kiro IDE that enables AI-assisted operations such as:
This MCP runs locally and never exposes Tomcat over the network.
Tomcat MCP is officially published to the MCP Registry and npm.
Registry name: io.github.sarath-451/tomcat-mcp
npm package: @sarath-451/tomcat-mcp
Search via Registry API: https://registry.modelcontextprotocol.io/v0.1/servers?search=tomcat
Make sure you have cloned this repository and installed dependencies first.
\- \\Node.js 18+\\
\- \\Java JDK\\ (required for jcmd, thread dumps, heap dumps)
\- Apache Tomcat (9 / 10 / 10.1 tested)
\- Windows (Linux support planned)
Check:
node -v
java -version
jcmd -h~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.