Verune

MCP server

npx-vibe

Read-only npm package and project dependency preflight tools for AI applications.

Version
3.0.0
Analysed
Last observed

What the code does

  • Starts other processes Code that launches separate programs.
  • Refers to credential files Code that names files such as SSH keys or cloud credentials.
  • Downloads and runs code Code that fetches a script and pipes it into a shell.
  • Evaluates code at runtime Code that builds and runs code while it executes.
  • Reads AI and developer logins Code that refers to AI tool credentials or publishing tokens, such as .npmrc.
  • Adds itself to startup Code that writes shell startup files, scheduled tasks or agent and editor settings.

Having a capability is not wrongdoing; many tools need these to do their job. It tells you what to check before you install.

This is public metadata, not a safety certification or complete assessment. Static analysis cannot establish what a tool does at runtime.

Risk

Sign in to see this tool's overall risk level and what drives it. Free.

Sign in to see the risk level

Coverage

Complete static analysis

How coverage is measured

Detailed report

8 findings from automated static analysis of the latest version, with severities and explanations.

Sign in to view detailed report

Using this tool across your team? We can assess your whole inventory.

Request an inventory assessment