io.github.KryptosAI/mcp-observatory
io.github.KryptosAI/mcp-observatory
MCP security scanner. CI-native testing, attack simulation, health scoring, and SARIF.
MITmedium
96.0
/ 100 activity
rank #330
How this score was reached
Every point is accounted for below. The weights are published on the methodology page and come from the same code that computes them.
recency
35 / 35
Last pushed 5 days ago, within the 30-day full-marks window.
responsiveness
20 / 20
10 open issues against 146 stars (ratio 0.06; full marks at or below 0.10, zero at 1.00 or above).
cadence
15 / 15
Registry entry updated 37 days ago, within the 90-day release window.
community
11 / 15
146 stars and 9 contributors, log-scaled so large outliers do not dominate.
metadata
15 / 15
Publisher metadata has OSI-approved licence (MIT), a substantive description, a declared repository link.
Risk flags
Static observations from published metadata. Nothing is installed or executed, and these are deliberately kept out of the score above.
medium
Package runs an install script
The published package defines postinstall script, which run on the installing machine before the server is started.
Native modules legitimately need this. It is flagged because it is also the usual supply-chain exfiltration vector — review the script, do not assume malice.
Score over time
2 readings, oldest first. Latest 96.0.
Registry record
- Repository
- https://github.com/KryptosAI/mcp-observatory
- Version
- 1.36.1
- Licence
- MIT
- GitHub
- 146 stars · 13 forks · 10 open issues · 9 contributors
- Last push
- Packages
- npm: @kryptosai/mcp-observatory@1.36.1
- Registry updated
- First indexed
Something wrong here? This index reads public registry and GitHub data; if a record is stale or misattributed, email contact@klars.ai.