io.github.jdhart81/security-preflight

security-preflight

Static MCP, source-code and injection-indicator checks with redacted signed receipts.

1.3.1
Version
remote
Transport
5
Tools

Security review

Review passed

Reviewed 1d ago.

  • tools: 5 tools scanned
  • metadata: scanned

No findings.

Tools (5)

  • security_preflight

    Run a $1 static Security Preflight and return a signed receipt. Direct MCP requires the checkout caller and verified fixed-order session. The separate x402 HTTP rail retains its existing introductory quote policy. No deployed endpoint is fetched or tested. Importing the receipt into an Agent Market profile is a separate, explicit action.

  • scan_source

    $1 bounded inline VulnCanon source scan; indicators, not proven exploits. Direct MCP requires the checkout caller and verified fixed-order session. At most 64 KiB, 2000 lines, 4096 characters per line. No model calls, repository fetching or code execution. Returns a redacted signed receipt.

  • screen_injection

    $1 batch of 1–20 text samples screened for deterministic injection markers. Direct MCP requires the checkout caller and verified fixed-order session. Maximum 64 KiB total. Heuristic indicators, not calibrated probabilities or a guarantee of safety. No model calls or automatic follow-on purchase.

  • get_security_receipt

    Read an unsigned, filtered public view; retain original delivery for signature verification.

  • describe_agent

    Describe scope, evidence boundary, inputs, and outputs.