MCP/Risk

Scan report

soma-rmcp

npm, scanned 2026-09-09, tool surface via none

This page reports an automated security scan of soma-rmcp (npm), scanned 2026-09-09. It rates trust (provenance, transport, known vulnerabilities, instruction integrity) as grade C and capability risk (what the tools can do) separately at unknown. It does not certify the server is safe to connect; it reports what could be checked from outside.

Automated checks

StatusCheckPolicyResult
WARN Listed on the official MCP registry §1.1

Not found on the official MCP registry. Not disqualifying, but listed servers carry namespace-verified provenance.

PASS Source repository is public and maintained §1.2
Active repository with a license. 5 findings
  • Repository
  • Last push: 2 days ago
  • Stars: 1
  • License: AGPL-3.0
  • Security policy (SECURITY.md): absent
FAIL Published package is consistent and attested §1.3
Integrity concerns: package repository field does not match the claimed source repo; no npm provenance attestation. 6 findings
  • Package: soma-rmcp@?
  • Ecosystem: npm
  • Age: 59 days
  • Weekly downloads: unknown
  • Repo field matches source repo: false
  • Build-provenance attestation: absent
UNVERIFIABLE Tool surface is inspectable and proportionate §2.1–§2.4

Tool surface could not be inspected (no reachable tools/list, no public package source). Per policy, unverifiability caps the overall grade.

INFO Transport & authentication §3

Local (stdio) server: runs with host-process privileges by design. Transport checks apply to remote servers; scrutiny shifts to §1/§2.

PASS No known vulnerabilities (OSV.dev) §4.1

No advisories on record for soma-rmcp (npm).

UNVERIFIABLE Server-supplied instructions free of poisoning indicators §5.1–§5.4

No server-supplied instructions or tool descriptions were obtainable to scan.

Verify manually - the scoring model can’t judge these for you

  • §2.3 - Is the tool surface no broader than the server’s stated purpose requires?
  • §3.4 - For stdio servers: which environment credentials does it read, and are they scoped rather than org-wide tokens?
  • §6.1 - Cross this server’s capabilities with your already-connected servers: any read-capability × send-capability pairs need explicit sign-off.
  • §6.2 - Run the connecting agent with sandboxing and egress controls sized to the combined tool surface, not just this server’s.

Methodology: MCP Server Security Policy. Checks and scoring weights are open source. Unfamiliar term? See the glossary.