idea-reality-mcp
PyPI
v0.5.0
Published by mnemox-ai — no publish provenance and no vendor-owned scope, so the publisher could not be verified. The repository link below is self-declared.
Every server starts at 100. These are the exact deductions the deterministic engine applied — each one reproducible, none of it an opinion or an LLM's guess:
| Points | What was found | Category |
|---|---|---|
| −33 | Hardcoded JSON Web Token in server code ×2 MTC-SRC-008 | exfiltration |
| −2.1 | Package has no source repository MTC-SUP-011 | supply-chain |
Grade capped: 2 confirmed high findings → grade capped at D. A hard gate overrides the point total — no amount of clean surface buys back a confirmed catastrophe.
Capability observations and info notes are shown under Findings but never scored.
Open any row's finding below for the file, line and evidence behind the deduction.
A live-looking JSON Web Token is hardcoded in `scripts/import_discord_to_turso.py:21`. Secrets in source ship to everyone who installs the package and are a direct credential leak.
Evidence: JSON Web Token: eyJh…(redacted)
Fix: Remove the secret, rotate it, and load credentials from the environment or a secret store.
Location: server scripts/import_discord_to_turso.py
A live-looking JSON Web Token is hardcoded in `scripts/init_turso.py:6`. Secrets in source ship to everyone who installs the package and are a direct credential leak.
Evidence: JSON Web Token: eyJh…(redacted)
Fix: Remove the secret, rotate it, and load credentials from the environment or a secret store.
Location: server scripts/init_turso.py
"idea-reality-mcp" declares no repository URL, so its published artifact cannot be compared against reviewable source.
Fix: Prefer packages that link to public, reviewable source.
Location: package idea-reality-mcp
Scan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.
| Version | Score | Findings | Engine | Scanned |
|---|---|---|---|---|
v0.5.0 latest |
D 65/100 | 3 | 1.5.0 | 2026-07-22 |
Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.
The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.
npx mcptrustchecker scan idea-reality-mcp --online --registry pypi
Security scan results for the 199bio Mcp Limitless MCP server.
Security scan results for the 1mcp MCP server.
Security scan results for the 1stay MCP server.
Generates production-ready UI components from natural language, inspired by v0.
Security scan results for the 2slides MCP server.
Security scan results for the 3d MCP server.