Verune

Check an AI agent tool before your team installs it.

Search MCP servers, plugins and agent skills. See how much of each one we could inspect, and read reviewed findings where a report exists.

Trygithubfilesystembrowserpostgres

Tools tracked
37,648
Analysed
15,046
Risk-scored
1,092
Last analysis
9 minutes ago

Results cover indexed public AI-agent tools. A missing record does not mean a tool is safe, unscanned, or absent from our broader research.

What the code does

Capabilities our static analysis found in the latest published version. Having one is not wrongdoing: many tools need them to do their job. It tells you what to check before you install.

Runs shell commands

Code that starts system commands on the machine it runs on.

Sends data to outside servers

Code that posts data to network addresses.

Refers to credential files

Code that names files such as SSH keys or cloud credentials.

Downloads and runs code

Code that fetches a script and pipes it into a shell.

Brings outside content into the agent

Tools that return web pages, search results, documentation or messages written by others. That text reaches the model, and instructions planted in it can steer the agent (indirect prompt injection). Treat what these tools return as untrusted input.

Runs hooks automatically

Hooks that execute without being called explicitly.

Changed without a new version

Published content changed while the version number stayed the same.

Recently indexed

Updated as the crawlers find new releases

Aptora

MCP server

Complete static analysis

Detailed report available

TripleBooks

MCP server

Complete static analysis

Detailed report available

Tribeunal

MCP server

Complete static analysis

Detailed report available

Need to know which tools your whole team already runs? We can assess your inventory.

Request an inventory assessment