@layers/mcp-server
npm
v1.3.2
Source verified
Published by layers — publish provenance cryptographically ties this package to that repository. That is proof of origin, not an official vendor package.
MCP server exposing the Layers API as tools
The grade answers one question — how safe is this server for you to adopt — so it is computed in two auditable stages. Nothing below is an opinion or an LLM's guess; every line is a real term the deterministic engine applied, and the same input always yields the same number.
1. Threat score — 100 − 0 = 100. What the published surface and source actually contain:
The deterministic scan raised no scored threat in the surface it inspected — the threat score stayed at 100. Capability observations and advisory notes are recorded but never lower it.
2. Client adoption risk — 100 − 6 = 94. Three small, subtract-only factors that reflect your risk in adopting it — a clean scan proves less on a powerful, unverified or barely-inspectable package, so the grade says so plainly:
| Points | Adoption-risk factor |
|---|---|
| −6 | capability blast radius (high) — client exposure if the model is manipulated |
Capability observations and info notes are shown under Findings but never scored.
Open any row's finding below for the file, line and evidence behind a deduction.
In the server's implementation (`dist/onboarding/collector-host.js:1`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: rt { spawn } from "node:child_process"; import { createHash, randomBytes } from "node:crypto"; import { constants as fsC
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server dist/onboarding/collector-host.js
Tool "upload_content_from_url" takes a URL/host parameter "url" with no allowlist/pattern. An outbound-request tool with an unbounded destination enables SSRF and cloud-metadata access (e.g. 169.254.169.254).
Fix: Allowlist destinations or constrain the parameter; block private/link-local addresses server-side.
Location: tool upload_content_from_url · inputSchema.properties.url
Each tool and what it can reach — statically extracted from the published source.
get_influenceringests untrusted inputget_projectingests untrusted inputupload_content_from_urlingests untrusted inputapprove_contentno sensitive capabilityarchive_projectno sensitive capabilityask_elleno sensitive capabilitycancel_scheduled_postno sensitive capabilityclone_influencerno sensitive capabilitycreate_content_uploadno sensitive capabilitycreate_influencerno sensitive capabilitycreate_projectno sensitive capabilitydelete_influencerno sensitive capabilityfinalize_content_uploadno sensitive capabilitygenerate_slideshowno sensitive capabilitygenerate_slideshow_remixno sensitive capabilitygenerate_ugc_remixno sensitive capabilitygenerate_video_remixno sensitive capabilityget_contentno sensitive capabilityget_content_assetno sensitive capabilityget_content_progressno sensitive capabilityget_content_review_policyno sensitive capabilityget_creditsno sensitive capabilityget_engagement_configno sensitive capabilityget_hooksno sensitive capabilityget_keywordsno sensitive capabilityget_metricsno sensitive capabilityget_onboarding_statusno sensitive capabilityget_scheduled_postno sensitive capabilityget_source_recommendationsno sensitive capabilityget_top_performersno sensitive capabilitylist_ads_contentno sensitive capabilitylist_audit_logno sensitive capabilitylist_contentno sensitive capabilitylist_credit_eventsno sensitive capabilitylist_influencersno sensitive capabilitylist_projectsno sensitive capabilitylist_recommendationsno sensitive capabilitylist_scheduled_postsno sensitive capabilitylist_social_accountsno sensitive capabilitylist_tiktok_musicno sensitive capabilitynotify_deviceno sensitive capabilityonboard_claim_beginno sensitive capabilityonboard_claim_verifyno sensitive capabilityonboard_startno sensitive capabilitypublish_contentno sensitive capabilityrefresh_keywordsno sensitive capabilityreject_contentno sensitive capabilityreschedule_postno sensitive capabilityschedule_contentno sensitive capabilityupdate_ads_contentno sensitive capabilityupdate_content_captionno sensitive capabilityupdate_content_review_policyno sensitive capabilityupdate_engagement_configno sensitive capabilityupdate_influencerno sensitive capabilityupdate_projectno sensitive capabilityupdate_recommendationno sensitive capabilitywhoamino sensitive capabilityScan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.
| Version | Score | Findings | Engine | Scanned |
|---|---|---|---|---|
v1.3.2 latest |
A 94/100 | 2 | 1.13.0 | 2026-09-07 |
v1.3.1 |
A 94/100 | 2 | 1.12.1 | 2026-08-18 |
v1.3.0 |
A 94/100 | 2 | 1.12.1 | 2026-08-17 |
v1.2.3 |
A 94/100 | 2 | 1.12.1 | 2026-08-16 |
v1.2.2 |
A 94/100 | 2 | 1.12.1 | 2026-08-15 |
v1.2.0 |
A 94/100 | 2 | 1.12.1 | 2026-08-14 |
v1.1.2 |
A 97/100 | 1 | 1.12.1 | 2026-08-14 |
v1.1.0 |
A 97/100 | 1 | 1.12.1 | 2026-08-12 |
v1.0.0 |
A 96/100 | 1 | 1.12.1 | 2026-07-29 |
Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.
The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.
npx mcptrustchecker scan @layers/mcp-server --online
Official Abyssfall game info, newsletter double opt-in, and merch reservation tools.
AdCritter ads platform: docs, API reference, app scaffolding, and white-label integration.
Google AdSense MCP Server - Monitor earnings, reports, and account health via Claude/AI
Operational empathy for technical founders + PE/VC operators navigating high-stakes B2B interactions. 28 MCP tools + CLI: ICP scoring, persona simulation, battlecards, deal classification, prospect discovery, investor matching, founder wellness, plus mark
MCP server for Bing Webmaster Tools — SEO site management, URL submission, sitemaps, stats, keywords
MCP (Model Context Protocol) server that helps AI agents use Primer Brand (@primer/react-brand) correctly when building GitHub marketing and landing pages.