Verune

MCP server

io.github.manumarri-sudo/quill

Pre-execution gate for AI-agent tool calls. Touch ID approval. Tamper-evident audit log.

Version
0.2.0a5
Analysed
Last observed

What the code does

  • Runs shell commands Code that starts system commands on the machine it runs on.
  • Sends data to outside servers Code that posts data to network addresses.
  • Refers to credential files Code that names files such as SSH keys or cloud credentials.
  • Downloads and runs code Code that fetches a script and pipes it into a shell.
  • Runs an AI coding agent unsupervised Code that starts an AI coding agent with its approval prompts switched off.
  • Asks your agent's AI to write text The server can request text from the agent's own model (MCP sampling).

Having a capability is not wrongdoing; many tools need these to do their job. It tells you what to check before you install.

This is public metadata, not a safety certification or complete assessment. Static analysis cannot establish what a tool does at runtime.

Risk

Sign in to see this tool's overall risk level and what drives it. Free.

Sign in to see the risk level

Coverage

Complete static analysis

How coverage is measured

Detailed report

7 findings from automated static analysis of the latest version, with severities and explanations.

Sign in to view detailed report

Using this tool across your team? We can assess your whole inventory.

Request an inventory assessment