@accesslint/mcp
MCP server for accessible agentic coding — WCAG audit tools for AI coding agents
19
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
ckundo
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@accesslint/chrome | AI (phantom-deps): Same-org dep declared in package.json; phantom-dep heuristic fires because it's not directly imported at the top level. | ai | |
| provenance | slsa-provenance | AI (provenance): SLSA provenance attestation present; stable positive signal for this package. | ai | |
| dependencies | unvetted-dep:@accesslint/cli | AI (dependencies): Sibling package from the same AccessLint org/monorepo; stable false positive for this package. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): CI/CD automated publishing with SLSA provenance; rapid publish is expected in this workflow. | ai | |
| source-diff | source-size-dropped | AI (source-diff): Size drop explained by extraction of logic into @accesslint/core dependency; not a stub/redirect. | ai | |
| provenance | publisher-changed | AI (provenance): Transition from human publisher to GitHub Actions CI with SLSA provenance; consistent with legitimate automation migration. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): chrome-launcher and chrome-remote-interface are legitimate, established browser automation deps appropriate for an accessibility audit tool. | ai | |
| typosquat | typosquat.levenshtein:yup | AI (typosquat): Scoped @accesslint package; Levenshtein match to 'yup' is coincidental, not impersonation. | ai |