@lexq/cli
npm
v0.1.59
Source verified
Published by lexq-io — publish provenance cryptographically ties this package to that repository. That is proof of origin, not an official vendor package.
LexQ CLI — manage policies, simulate rules, and deploy from the terminal. Built for humans and AI agents.
The grade answers one question — how safe is this server for you to adopt — so it is computed in two auditable stages. Nothing below is an opinion or an LLM's guess; every line is a real term the deterministic engine applied, and the same input always yields the same number.
1. Threat score — 100 − 0 = 100. What the published surface and source actually contain:
The deterministic scan raised no scored threat in the surface it inspected — the threat score stayed at 100. Capability observations and advisory notes are recorded but never lower it.
2. Client adoption risk — 100 − 6 = 94. Three small, subtract-only factors that reflect your risk in adopting it — a clean scan proves less on a powerful, unverified or barely-inspectable package, so the grade says so plainly:
| Points | Adoption-risk factor |
|---|---|
| −6 | capability blast radius (high) — client exposure if the model is manipulated |
Capability observations and info notes are shown under Findings but never scored.
Open any row's finding below for the file, line and evidence behind a deduction.
Tool "lexq_webhook_subscriptions_save" can both read sensitive data and send data to an external destination. Even without an explicit untrusted-input leg, this is a single-call data-exfiltration path if the model is ever manipulated.
Fix: Separate reading from sending; require explicit user confirmation before egress of file/secret contents.
Location: flow lexq_webhook_subscriptions_save
Tools that read sensitive data ([lexq_webhook_subscriptions_save]) and tools that can send data out ([lexq_webhook_subscriptions_get, lexq_webhook_subscriptions_save, lexq_webhook_subscriptions_delete, lexq_webhook_subscriptions_test]) are exposed together. An agent can move private data to the sink.
Evidence: sources [lexq_webhook_subscriptions_save] → sinks [lexq_webhook_subscriptions_get, lexq_webhook_subscriptions_save, lexq_webhook_subscriptions_delete, lexq_webh
Fix: Keep secret-reading and egress capabilities on separate, separately-approved servers.
Location: flow lexq_webhook_subscriptions_save → lexq_webhook_subscriptions_get
Each tool and what it can reach — statically extracted from the published source.
lexq_webhook_subscriptions_savenetwork egressreads sensitive datalexq_webhook_subscriptions_deletenetwork egresslexq_webhook_subscriptions_getnetwork egresslexq_webhook_subscriptions_testnetwork egresslexq_ab_test_adjustno sensitive capabilitylexq_ab_test_startno sensitive capabilitylexq_ab_test_stopno sensitive capabilitylexq_dataset_templateno sensitive capabilitylexq_dataset_uploadno sensitive capabilitylexq_deploy_deployableno sensitive capabilitylexq_deploy_detailno sensitive capabilitylexq_deploy_diffno sensitive capabilitylexq_deploy_historyno sensitive capabilitylexq_deploy_liveno sensitive capabilitylexq_deploy_overviewno sensitive capabilitylexq_deploy_publishno sensitive capabilitylexq_deploy_rollbackno sensitive capabilitylexq_deploy_scheduleno sensitive capabilitylexq_deploy_schedulesno sensitive capabilitylexq_deploy_undeployno sensitive capabilitylexq_deploy_unscheduleno sensitive capabilitylexq_domain_templates_applyno sensitive capabilitylexq_domain_templates_listno sensitive capabilitylexq_domain_templates_previewno sensitive capabilitylexq_dry_runno sensitive capabilitylexq_dry_run_compareno sensitive capabilitylexq_facts_action_metadatano sensitive capabilitylexq_facts_createno sensitive capabilitylexq_facts_deleteno sensitive capabilitylexq_facts_exportno sensitive capabilitylexq_facts_listno sensitive capabilitylexq_facts_unregisteredno sensitive capabilitylexq_facts_updateno sensitive capabilitylexq_groups_createno sensitive capabilitylexq_groups_deleteno sensitive capabilitylexq_groups_getno sensitive capabilitylexq_groups_listno sensitive capabilitylexq_groups_reorderno sensitive capabilitylexq_groups_updateno sensitive capabilitylexq_history_getno sensitive capabilitylexq_history_listno sensitive capabilitylexq_history_statsno sensitive capabilitylexq_logs_actionno sensitive capabilitylexq_logs_bulk_actionno sensitive capabilitylexq_logs_getno sensitive capabilitylexq_logs_listno sensitive capabilitylexq_pii_reveals_listno sensitive capabilitylexq_profile_overviewno sensitive capabilitylexq_profile_ruleno sensitive capabilitylexq_provenance_getno sensitive capabilitylexq_replay_cancelno sensitive capabilitylexq_replay_decisionno sensitive capabilitylexq_replay_exportno sensitive capabilitylexq_replay_listno sensitive capabilitylexq_replay_startno sensitive capabilitylexq_replay_statusno sensitive capabilitylexq_requirementsno sensitive capabilitylexq_rules_createno sensitive capabilitylexq_rules_deleteno sensitive capabilitylexq_rules_getno sensitive capabilitylexq_rules_listno sensitive capabilitylexq_rules_reorderno sensitive capabilitylexq_rules_toggleno sensitive capabilitylexq_rules_updateno sensitive capabilitylexq_simulation_cancelno sensitive capabilitylexq_simulation_exportno sensitive capabilitylexq_simulation_listno sensitive capabilitylexq_simulation_startno sensitive capabilitylexq_simulation_statusno sensitive capabilitylexq_versions_cloneno sensitive capabilitylexq_versions_createno sensitive capabilitylexq_versions_deleteno sensitive capabilitylexq_versions_getno sensitive capabilitylexq_versions_listno sensitive capabilitylexq_versions_updateno sensitive capabilitylexq_webhook_subscriptions_listno sensitive capabilitylexq_whoamino sensitive capabilityCross-tool combinations that form a data-exfiltration primitive (untrusted input → sensitive source → external sink).
Scan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.
| Version | Score | Findings | Engine | Scanned |
|---|---|---|---|---|
v0.1.59 latest |
A 94/100 | 2 | 1.13.0 | 2026-09-09 |
v0.1.58 |
A 94/100 | 2 | 1.13.0 | 2026-09-07 |
v0.1.56 |
A 94/100 | 2 | 1.13.0 | 2026-08-29 |
v0.1.54 |
A 94/100 | 2 | 1.13.0 | 2026-08-28 |
v0.1.53 |
A 94/100 | 2 | 1.13.0 | 2026-08-25 |
v0.1.52 |
A 94/100 | 2 | 1.12.1 | 2026-08-24 |
v0.1.50 |
A 94/100 | 2 | 1.12.1 | 2026-08-23 |
v0.1.49 |
A 94/100 | 2 | 1.12.1 | 2026-08-22 |
v0.1.48 |
A 94/100 | 2 | 1.12.1 | 2026-08-21 |
v0.1.46 |
A 94/100 | 2 | 1.12.1 | 2026-08-20 |
Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.
The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.
npx mcptrustchecker scan @lexq/cli --online
Hotel booking MCP server — 300K+ properties, real confirmation numbers, loyalty programs. Builders monetize every booking via Stripe Connect. The first MCP server that completes real hotel reservations inside AI conversations.
Manage AdGuard Home through AI assistants
Read-only Azure DevOps for MCP clients using only your existing browser session — no PAT, no Azure CLI. Browse work items, pull requests, comments, attachments and Artifacts feeds across every project, repo and feed you can access.
MCP server for Adobe Experience Manager Assets integration development
Servidor MCP para el tiempo oficial de España (API pública OpenData de AEMET). Predicción, observación y avisos como herramientas MCP tipadas.
A standalone MCP stdio bridge for Affinity by Canva's local MCP SSE server.