shortcut — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited shortcut (Plugin) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A lightweight Shortcut MCP deployed on Cloudflare Workers. One tool, ten actions.
Live URL: https://streamshortcut.staycek.workers.dev/mcp
The official @shortcut/mcp uses ~11,652 tokens for tool definitions (52 tools). StreamShortcut uses ~393 tokens — a 96.6% reduction.
| Action | Purpose |
|---|---|
search | Find stories (default: your active stories) |
get | Story details by ID or URL |
update | Change state, estimate, owner |
comment | Add comment to story |
create | Create new story |
stories | List stories with filters |
workflows | List workflows and states |
members | List team members |
projects | List projects |
api | Raw REST API |
help | Documentation |
You must provide your own Shortcut API token. Get one at: https://app.shortcut.com/settings/account/api-tokens
Add to your Claude Desktop config:
{
"mcpServers": {
"shortcut": {
"type": "http",
"url": "https://streamshortcut.staycek.workers.dev/mcp",
"headers": {
"X-Shortcut-Token": "your-token-here"
}
}
}
}Or set the SHORTCUT_API_TOKEN environment variable and use:
{
"mcpServers": {
"shortcut": {
"type": "http",
"url": "https://streamshortcut.staycek.workers.dev/mcp",
"headers": {
"X-Shortcut-Token": "${SHORTCUT_API_TOKEN}"
}
}
}
}If you prefer to self-host:
git clone https://github.com/stayce/streamshortcut-cloudflare
cd streamshortcut-cloudflare
npm install npm run deployNo server-side secrets needed — users always provide their own token.
{"action": "search"}
{"action": "get", "id": "704"}
{"action": "update", "id": "704", "state": "Done"}
{"action": "comment", "id": "704", "body": "Fixed!"}
{"action": "create", "name": "New bug", "type": "bug"}
{"action": "workflows"}
{"action": "members"}
{"action": "api", "method": "GET", "path": "/projects"}
{"action": "help"}MIT
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.