MCP server · trust report

ai.hermitsh/texts

1 check that ran failed — version behavior — so this release can’t be trusted as-is.

Publisher
ai.hermitsh
Repository
Install
npm:@hermitsh/texts-mcp
Versions
3
Inspected
5 of 6 checks · 75%
Scored
2026-09-04 · rubric 1.0.0

What we checked

Six static checks, weighted by risk. Every result reflects only what could be observed in the published package and repository — never intent.

6 checks1 clean4 flagged1 not inspected
  • Injection surface

    unscannable25% of grade

    Tool descriptions/manifest scanned for instruction-injection patterns (imperatives at the model, hidden text, 'ignore previous', data-exfil URLs).

    No tool descriptions, server instructions, prompts, or resources were fetched; nothing to scan for injection.

  • Supply chain

    warn25% of grade

    Package provenance: namespace verification, repo linkage, maintainer count, account age, postinstall scripts, typosquat distance.

    no resolvable repository linked to the package (provenance unverifiable)

  • Credential hygiene

    pass15% of grade

    How the server takes secrets (env vs plaintext config vs hardcoded); secrets appearing in tool schemas.

    No hardcoded secrets, secret-shaped tool parameters, or leaked keys found. PASS = no static red flag; static analysis cannot prove the code honors env-based secret handling at runtime.

  • Permission scope

    warn15% of grade

    Declared tools vs. breadth (filesystem, network, exec); flags shell-exec and unbounded filesystem access.

    discloses shell/exec capability: bin/hermitsh-texts-mcp.js: imports child_process and calls exec/spawn Capability DISCLOSURE, not a verdict: static analysis sees the primitive is present and reachable, not whether its use is attacker-controlled.

  • Version behavior

    fail10% of grade

    Diff of tool definitions between versions; new permissions or changed descriptions in a patch release (the postmark-mcp class).

    vs prior 0.5.0 (patch bump): new capability primitive(s) in source: child_process; new hardcoded outbound host/BCC destination(s): hermitsh.ai.

  • Transport config

    warn10% of grade

    Remote servers: TLS and auth mode (none/token/OAuth). Local servers: whether the manifest indicates it phones home.

    remote endpoint present with no declared auth mode (unable to confirm authentication)

Version history

Each release plotted by grade against the safe line at B. A version that sinks below the line has lost its trusted standing — the shape of a rug-pull.

VersionPublishedGradeScoreInspectedChange
v0.5.1 · current2026-08-16 C655/6 · 75%B→C in v0.5.1
v0.5.02026-07-05 B77.54/6 · 75%