run402-mcp
npm
v4.70.9
Source verified
Published by kychee-com — publish provenance cryptographically ties this package to that repository. That is proof of origin, not an official vendor package.
MCP server for Run402 — AI-native Postgres databases with REST API, auth, storage, and row-level security. Pay with x402 USDC micropayments.
The grade answers one question — how safe is this server for you to adopt — so it is computed in two auditable stages. Nothing below is an opinion or an LLM's guess; every line is a real term the deterministic engine applied, and the same input always yields the same number.
1. Threat score — 100 − 0 = 100. What the published surface and source actually contain:
The deterministic scan raised no scored threat in the surface it inspected — the threat score stayed at 100. Capability observations and advisory notes are recorded but never lower it.
2. Client adoption risk — 100 − 10 = 90. Three small, subtract-only factors that reflect your risk in adopting it — a clean scan proves less on a powerful, unverified or barely-inspectable package, so the grade says so plainly:
| Points | Adoption-risk factor |
|---|---|
| −10 | capability blast radius (critical) — client exposure if the model is manipulated |
Capability observations and info notes are shown under Findings but never scored.
Open any row's finding below for the file, line and evidence behind a deduction.
This server (without client built-ins) exposes a complete data-exfiltration chain: assets_get → list_secrets → delete_mailbox_webhook. Untrusted input is ingested, private data is read, and it can be sent to an external sink via the agent composing the tools (→). Static analysis proves the primitive exists, not that a specific run will occur.
Fix: Remove one leg of the trifecta: isolate untrusted-input tools from secret-reading tools and from egress tools, or require human approval between them.
Location: flow assets_get → list_secrets → delete_mailbox_webhook
In the server's implementation (`sdk/dist/node/files.js:16`): Reading private keys / cloud credentials, or serializing the whole environment, is a sensitive-data source that becomes exfiltration when combined with any egress. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: env", ".envrc", ".npmrc", ".pnpmrc", ".yarnrc", ".netrc", ".pypirc", "id_dsa", "id_ecdsa
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server sdk/dist/node/files.js
In the server's implementation (`sdk/dist/node/gitvault-snapshot.js:697`): Reading private keys / cloud credentials, or serializing the whole environment, is a sensitive-data source that becomes exfiltration when combined with any egress. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: "*.keystore", "id_rsa*", "id_ed25519*", "id_ecdsa*", ".npmrc", ".netrc", ".pypirc", ".g
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server sdk/dist/node/gitvault-snapshot.js
In the server's implementation (`sdk/dist/node/actions-node.js:2`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: { execFile } from "node:child_process"; import { lstat, mkdir, mkdtemp, readFile, rename, rm, writeFile, } from "node:fs
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server sdk/dist/node/actions-node.js
In the server's implementation (`sdk/dist/node/gitvault-restore.js:27`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: { execFile } from "node:child_process"; import { mkdtempSync, existsSync, readFileSync, appendFileSync, mkdirSync } from
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server sdk/dist/node/gitvault-restore.js
In the server's implementation (`sdk/dist/node/gitvault-snapshot.js:47`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: { execFile } from "node:child_process"; import { existsSync, lstatSync, mkdirSync, mkdtempSync, readFileSync, readlinkSy
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server sdk/dist/node/gitvault-snapshot.js
Each tool and what it can reach — statically extracted from the published source.
assets_getingests untrusted inputbrowse_appsingests untrusted inputdelete_mailbox_webhooknetwork egressdeploy_diagnose_urlingests untrusted inputget_function_runingests untrusted inputget_function_run_logsingests untrusted inputjobs_download_artifactingests untrusted inputlist_secretsreads sensitive datapreview_project_transferingests untrusted inputredrive_mailbox_webhook_deliverynetwork egressregister_mailbox_webhooknetwork egressrotate_webhook_secretnetwork egressrun_sqlreads sensitive datasend_emailnetwork egressset_notification_preferencesnetwork egressupdate_mailbox_webhooknetwork egressaccept_project_transferno sensitive capabilityack_room_messageno sensitive capabilityadmin_archive_projectno sensitive capabilityadmin_reactivate_projectno sensitive capabilityadmin_set_lease_perpetualno sensitive capabilityai_moderateno sensitive capabilityai_translateno sensitive capabilityai_usageno sensitive capabilityallowance_createno sensitive capabilityallowance_exportno sensitive capabilityallowance_statusno sensitive capabilityapp_upno sensitive capabilityapply_exposeno sensitive capabilityassets_lsno sensitive capabilityassets_putno sensitive capabilityassets_rmno sensitive capabilityassets_signno sensitive capabilityauth_settingsno sensitive capabilitybilling_historyno sensitive capabilitycancel_function_runno sensitive capabilitycancel_project_transferno sensitive capabilitycheck_balanceno sensitive capabilityci_create_bindingno sensitive capabilityci_get_bindingno sensitive capabilityci_list_bindingsno sensitive capabilityci_revoke_bindingno sensitive capabilityclaim_project_transferno sensitive capabilityclaim_room_resourceno sensitive capabilityclaim_subdomainno sensitive capabilitycontract_callno sensitive capabilitycontract_deployno sensitive capabilitycontract_readno sensitive capabilitycreate_auth_userno sensitive capabilitycreate_checkoutno sensitive capabilitycreate_email_organizationno sensitive capabilitycreate_function_runno sensitive capabilitycreate_mailboxno sensitive capabilitycreate_notification_ruleno sensitive capabilitycreate_orgno sensitive capabilitycreate_project_branchno sensitive capabilitycreate_project_snapshotno sensitive capabilitydelete_functionno sensitive capabilitydelete_mailboxno sensitive capabilitydelete_notification_ruleno sensitive capabilitydelete_passkeyno sensitive capabilitydelete_projectno sensitive capabilitydelete_project_branchno sensitive capabilitydelete_project_snapshotno sensitive capabilitydelete_secretno sensitive capabilitydelete_signerno sensitive capabilitydelete_subdomainno sensitive capabilitydelete_versionno sensitive capabilitydemote_userno sensitive capabilitydeployno sensitive capabilitydeploy_eventsno sensitive capabilitydeploy_functionno sensitive capabilitydeploy_listno sensitive capabilitydeploy_rehearseno sensitive capabilitydeploy_release_activeno sensitive capabilitydeploy_release_diffno sensitive capabilitydeploy_release_getno sensitive capabilitydeploy_resumeno sensitive capabilitydeploy_siteno sensitive capabilitydeploy_site_dirno sensitive capabilitydeploy_verify_edgeno sensitive capabilitydiagnose_public_urlno sensitive capabilitydomains_activateno sensitive capabilitydomains_applyno sensitive capabilitydomains_checkno sensitive capabilitydomains_disconnectno sensitive capabilitydomains_ensureno sensitive capabilitydomains_getno sensitive capabilitydomains_listno sensitive capabilitydomains_repairno sensitive capabilitydomains_test_receiveno sensitive capabilitydrain_signerno sensitive capabilityerrors_listno sensitive capabilityexport_project_archiveno sensitive capabilityfork_appno sensitive capabilityfunctions_rebuildno sensitive capabilitygenerate_imageno sensitive capabilityget_agent_contact_statusno sensitive capabilityget_appno sensitive capabilityget_buzz_routeno sensitive capabilityget_contract_call_statusno sensitive capabilityget_emailno sensitive capabilityget_email_rawno sensitive capabilityget_escalationno sensitive capabilityget_exposeno sensitive capabilityget_function_logsno sensitive capabilityget_mailboxno sensitive capabilityget_mailbox_webhookno sensitive capabilityget_notification_preferencesno sensitive capabilityget_operator_statusno sensitive capabilityget_orgno sensitive capabilityget_project_snapshotno sensitive capabilityget_quoteno sensitive capabilityget_schemano sensitive capabilityget_signerno sensitive capabilityget_usageno sensitive capabilityimport_project_archiveno sensitive capabilityinitno sensitive capabilityinitiate_project_transferno sensitive capabilityinspect_project_archiveno sensitive capabilityinvite_auth_userno sensitive capabilityinvoke_functionno sensitive capabilityjobs_cancelno sensitive capabilityjobs_getno sensitive capabilityjobs_logsno sensitive capabilityjobs_purgeno sensitive capabilityjobs_submitno sensitive capabilityjoin_roomno sensitive capabilitylink_wallet_to_organizationno sensitive capabilitylist_buzz_route_deliveriesno sensitive capabilitylist_emailsno sensitive capabilitylist_function_runsno sensitive capabilitylist_functionsno sensitive capabilitylist_incoming_transfersno sensitive capabilitylist_mailbox_webhook_deliveriesno sensitive capabilitylist_mailbox_webhooksno sensitive capabilitylist_mailboxesno sensitive capabilitylist_notification_channelsno sensitive capabilitylist_notification_rulesno sensitive capabilitylist_notificationsno sensitive capabilitylist_outgoing_transfersno sensitive capabilitylist_passkeysno sensitive capabilitylist_project_branchesno sensitive capabilitylist_project_eventsno sensitive capabilitylist_project_snapshotsno sensitive capabilitylist_projectsno sensitive capabilitylist_signersno sensitive capabilitylist_subdomainsno sensitive capabilitylist_tenant_paymentsno sensitive capabilitylist_versionsno sensitive capabilitypasskey_login_optionsno sensitive capabilitypasskey_login_verifyno sensitive capabilitypasskey_register_optionsno sensitive capabilitypasskey_register_verifyno sensitive capabilitypay_urlno sensitive capabilityproject_getno sensitive capabilityproject_key_cache_exportno sensitive capabilityproject_key_cache_statusno sensitive capabilityproject_useno sensitive capabilitypromote_userno sensitive capabilityprovision_postgres_projectno sensitive capabilityprovision_signerno sensitive capabilitypublish_appno sensitive capabilityraise_escalationno sensitive capabilityread_room_messagesno sensitive capabilityredeem_voucherno sensitive capabilityredrive_function_runno sensitive capabilityrelease_room_claimno sensitive capabilityrename_orgno sensitive capabilityrename_projectno sensitive capabilityrenew_project_branchno sensitive capabilityrequest_faucetno sensitive capabilityrequest_magic_linkno sensitive capabilityrest_queryno sensitive capabilityrestore_project_snapshotno sensitive capabilityscaffold_rolesno sensitive capabilitysend_feedbackno sensitive capabilitysend_room_messageno sensitive capabilityservice_healthno sensitive capabilityservice_statusno sensitive capabilityset_agent_contactno sensitive capabilityset_auto_rechargeno sensitive capabilityset_low_balance_alertno sensitive capabilityset_mailbox_defaultsno sensitive capabilityset_recovery_addressno sensitive capabilityset_secretno sensitive capabilityset_tierno sensitive capabilityset_user_passwordno sensitive capabilitystart_operator_passkey_enrollmentno sensitive capabilitystatusno sensitive capabilitytest_notificationno sensitive capabilitytier_statusno sensitive capabilityupdate_functionno sensitive capabilityupdate_mailboxno sensitive capabilityupdate_versionno sensitive capabilityvalidate_manifestno sensitive capabilityverify_agent_contact_emailno sensitive capabilityverify_magic_linkno sensitive capabilityverify_project_archiveno sensitive capabilitywait_for_cdn_freshnessno sensitive capabilityCross-tool combinations that form a data-exfiltration primitive (untrusted input → sensitive source → external sink).
Scan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.
| Version | Score | Findings | Engine | Scanned |
|---|---|---|---|---|
v4.70.9 latest |
A 90/100 | 6 | 1.13.0 | 2026-09-07 |
v4.69.8 |
A 90/100 | 6 | 1.13.0 | 2026-09-05 |
v4.69.2 |
A 90/100 | 6 | 1.13.0 | 2026-09-04 |
v4.65.0 |
A 90/100 | 4 | 1.13.0 | 2026-09-01 |
v4.60.0 |
A 90/100 | 4 | 1.13.0 | 2026-08-31 |
v4.56.2 |
A 90/100 | 4 | 1.13.0 | 2026-08-30 |
v4.49.0 |
A 90/100 | 4 | 1.13.0 | 2026-08-29 |
v4.45.1 |
A 90/100 | 4 | 1.13.0 | 2026-08-28 |
v4.40.0 |
A 90/100 | 4 | 1.13.0 | 2026-08-27 |
v4.31.0 |
A 90/100 | 4 | 1.13.0 | 2026-08-25 |
Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.
The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.
npx mcptrustchecker scan run402-mcp --online
Authenticated MCP transport with HTTP Signatures for AAuth agents
Local-first MCP server for parallel AI coding agents to claim file ownership before edits, preventing stomping on each other in the same worktree.
Agent-agnostic intercommunication system — sessions, messaging, channels, shared state, and real-time events
MCP server for AI agent task communication and delegation with diagnostic lifecycle visibility
Programmatic add/link/unlink for MCP servers across 23 AI coding agents (Claude Code, Claude Desktop, Cursor, VS Code, Codex, Gemini CLI, Zed, Cline, OpenCode, Goose, Kiro, Windsurf, and more). Functional API with dry-run support.
MCP server layer exposing agent-mesh orchestrator as an MCP agent