Independent MCP server safety profile · methodology
npm i)YES — runs arbitrary codeGET /mcp/verify?package=%40phnx-labs%2Fagents-cli. See the whole ecosystem in the State of MCP Security report, or browse all audited servers.GET /mcp/drift.json?packages=@phnx-labs/agents-cliНЕ ставить без ревью исходника: опасные признаки. Data from PulseFeed's independent MCP audit (last crawl 2026-08-20). An install script is not automatically malicious — native builds use them — but each is an unreviewed code-execution vector worth checking. All audited MCP servers →