steep-353a14 — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited steep-353a14 (Plugin) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
<!-- mcp-name: app.steep/mcp -->
This repository contains the configuration needed to integrate Steep with Claude Code, Cursor, and other MCP-compatible clients. The plugin lets your AI agents interact directly with your Steep workspace, querying metrics, targets, entities, and team data through natural language.
The Steep MCP server provides the following capabilities:
date range, with optional slicing and breakdowns
All tools are read-only.
Before setting up the Steep MCP server, ensure you have:
Install from the community plugin marketplace:
/plugin marketplace add anthropics/claude-plugins-community
/plugin install steep@claude-communityAlternatively, install directly from this repo:
git clone https://github.com/SteepHq/steep-mcp.git
claude --plugin-dir ./steep-mcpEither path loads .claude-plugin/plugin.json and the sibling .mcp.json, configures the Steep MCP server, and prompts you to authenticate via OAuth. No client ID is needed — Claude Code discovers the auth server and registers itself dynamically.
Install with one click from the Cursor plugin marketplace.
Alternatively, add Steep manually: Cursor → Settings → MCP and paste:
{
"mcpServers": {
"steep": {
"url": "https://mcp.steep.app/mcp"
}
}
}Save the configuration, then click the connect button to authenticate via OAuth.
Point your client at https://mcp.steep.app/mcp (Streamable HTTP transport). Clients supporting Dynamic Client Registration (RFC 7591) will register automatically.
Once configured, you can interact with Steep through your AI assistant using natural language:
Marketplace installs (Claude Code, Cursor) auto-update when we publish a new version. Run /plugin update steep in Claude Code to pull the latest.
Cursor handles updates through its own marketplace UI. Users who installed manually via --plugin-dir or by editing mcp.json directly will keep using whatever revision they cloned — re-clone or re-paste to get changes.
server. No local installation is required or supported.
already has access to. OAuth scopes are limited to the read scopes the server advertises at /.well-known/oauth-protected-resource.
For product questions and integration help, contact [email protected].
For security reports, see SECURITY.md.
Apache-2.0 — see LICENSE.
The Steep name and logo are trademarks of Steep. See NOTICE.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.