1 check that ran failed — permission scope — so this release can’t be trusted as-is.
- Publisher
- io.github.raphasouthall
- Repository
- github.com/raphasouthall/neurostack
- Install
- npm:neurostack, npm:neurostack
- Versions
- 2
- Inspected
- 4 of 6 checks · 65%
- Scored
- 2026-07-20 · rubric 1.0.0
What we checked
Six static checks, weighted by risk. Every result reflects only what could be observed in the published package and repository — never intent.
Injection surface
unscannable25% of gradeTool descriptions/manifest scanned for instruction-injection patterns (imperatives at the model, hidden text, 'ignore previous', data-exfil URLs).
No tool descriptions, server instructions, prompts, or resources were fetched; nothing to scan for injection.
Supply chain
warn25% of gradePackage provenance: namespace verification, repo linkage, maintainer count, account age, postinstall scripts, typosquat distance.
install hook "postinstall" present and not a recognized benign build command; install hook "preuninstall" present and not a recognized benign build command
Credential hygiene
pass15% of gradeHow the server takes secrets (env vs plaintext config vs hardcoded); secrets appearing in tool schemas.
Reads secrets from the environment (e.g. postinstall.js) — the recommended intake shape. PASS = no static red flag; static analysis cannot prove the code honors env-based secret handling at runtime.
Permission scope
fail15% of gradeDeclared tools vs. breadth (filesystem, network, exec); flags shell-exec and unbounded filesystem access.
HIGH: shell/exec capability AND destructive filesystem writes together (bin/neurostack.js: imports child_process and calls exec/spawn; bin/neurostack.js: path traversal ('../') combined with file access). discloses shell/exec capability: bin/neurostack.js: imports child_process and calls exec/spawn discloses shell/exec capability: postinstall.js: imports child_process and calls exec/spawn discloses broad/destructive filesystem access: bin/neurostack.js: path traversal ('../') combined with file access discloses broad/destructive filesystem access: postinstall.js: destructive/writing fs.* call (write/unlink/rm/chmod/rename) discloses broad/destructive filesystem access: preuninstall.js: destructive/writing fs.* call (write/unlink/rm/chmod/rename) Capability DISCLOSURE, not a verdict: static analysis sees the primitive is present and reachable, not whether its use is attacker-controlled.
Version behavior
unscannable10% of gradeDiff of tool definitions between versions; new permissions or changed descriptions in a patch release (the postmark-mcp class).
no prior version to diff (first sight of io.github.raphasouthall/[email protected]); version-drift / rug-pull cannot be evaluated. Cold-start risk is covered by point-in-time checks (injection_surface, supply_chain, credential_hygiene), not here.
Transport config
warn10% of gradeRemote servers: TLS and auth mode (none/token/OAuth). Local servers: whether the manifest indicates it phones home.
remote endpoint present with no declared auth mode (unable to confirm authentication)
Version history
Each release plotted by grade against the safe line at B. A version that sinks below the line has lost its trusted standing — the shape of a rug-pull.
| Version | Published | Grade | Score | Inspected | Change |
|---|---|---|---|---|---|
| v0.12.0 · current | 2026-03-31 | C | 67.5 | 4/6 · 65% | — |