Plugin
iris
The agent eval standard for MCP. Score every agent output for quality, safety, and cost. 12 built-in eval rules cover completeness, relevance, safety (PII detection, prompt injection), and cost thresholds. Log traces with hierarchical spans, evaluate outputs inline, and track costs across all your agents. No SDK, no code changes — add one line to your MCP config. Open source, MIT licensed.
- Analysed
- Last observed
What the code does
- Runs shell commands Code that starts system commands on the machine it runs on.
- Starts other processes Code that launches separate programs.
- Sends data to outside servers Code that posts data to network addresses.
- Evaluates code at runtime Code that builds and runs code while it executes.
- Runs hooks automatically Hooks that execute without being called explicitly.
Having a capability is not wrongdoing; many tools need these to do their job. It tells you what to check before you install.
This is public metadata, not a safety certification or complete assessment. Static analysis cannot establish what a tool does at runtime.
Risk
Sign in to see this tool's overall risk level and what drives it. Free.
Coverage
Detailed report
7 findings from automated static analysis of the latest version, with severities and explanations.
Using this tool across your team? We can assess your whole inventory.
Request an inventory assessment