Independent MCP server safety profile · methodology
npm i)noGET /mcp/verify?package=%40cjhyy%2Fcode-shell-core. See the whole ecosystem in the State of MCP Security report, or browse all audited servers.GET /mcp/drift.json?packages=@cjhyy/code-shell-coreПоддерживается, без опасных install-скриптов — можно ставить. Data from PulseFeed's independent MCP audit (last crawl 2026-08-20). An install script is not automatically malicious — native builds use them — but each is an unreviewed code-execution vector worth checking. All audited MCP servers →