← Home

@holoscript/mcp-server

Model Context Protocol server for HoloScript - enables AI agents to parse, validate, and generate HoloScript code

12
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

brianonbased

Keywords

holoscriptmcpmodel-context-protocolaivr3dxr

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@holoscript/core AI (phantom-deps): Same-org monorepo dep referenced via config; stable FP. ai
phantom-deps phantom-dep:ethers AI (phantom-deps): Common web3 lib; no evidence of misuse. ai
phantom-deps phantom-dep:ws AI (phantom-deps): Large multi-purpose dependency set typical of this monorepo; no malicious use evidenced. ai
phantom-deps phantom-dep:zod AI (phantom-deps): Likely used indirectly/in build; no malicious behavior found. ai
phantom-deps phantom-dep:viem AI (phantom-deps): Common web3 lib declared but not directly imported; benign. ai
phantom-deps phantom-dep:axios AI (phantom-deps): Common HTTP lib; no evidence of misuse. ai
phantom-deps phantom-dep:@opentelemetry/api AI (phantom-deps): Observability tooling; benign. ai
phantom-deps phantom-dep:ffmpeg-static AI (phantom-deps): Media utility dep; benign. ai
phantom-deps phantom-dep:loro-crdt AI (phantom-deps): Benign utility dep. ai
phantom-deps phantom-dep:qrcode AI (phantom-deps): Benign utility dep. ai
phantom-deps phantom-dep:playwright AI (phantom-deps): Test/browser automation dep, dual-use but expected here. ai
source-diff encoded-string-file:dist/index.mjs AI (source-diff): Same viem bytecode constants, bundling artifact. ai
source-diff encoded-string-file:dist/http-server.js AI (source-diff): Same viem bytecode constants, bundling artifact. ai
source-diff encoded-string-file:dist/index.js AI (source-diff): Same viem bytecode constants, bundling artifact. ai
source-diff encoded-string-file:dist/cli.mjs AI (source-diff): Same viem bytecode constants, bundling artifact. ai
source-diff encoded-string-file:dist/cli.js AI (source-diff): Hex-encoded viem/EVM bytecode constants bundled from a dependency, not obfuscated payload. ai
source-diff encoded-string-file:dist/http-server.mjs AI (source-diff): Same viem bytecode constants, bundling artifact. ai
provenance missing-githead AI (provenance): Publish env variance, no behavioral indicator; publisher has strong history. ai
publish-pattern new-deps-added AI (publish-pattern): pg and first-party @holoscript dep match stated DB/service functionality. ai
provenance no-provenance AI (provenance): Manual publish consistent with prior versions; not malicious. ai
phantom-deps phantom-dep:pg AI (phantom-deps): Monorepo deps referenced via config/runtime wiring, not direct import; stable FP. ai
semgrep semgrep:dynamic-require AI (semgrep): require(dist) resolves package's own build output, not arbitrary input. ai
phantom-deps phantom-dep:eventsource AI (phantom-deps): Used transitively/via config; not a real concern. ai
semgrep semgrep:child-process-import AI (semgrep): execSync in bin launcher start.js; standard CLI entrypoint pattern. ai

Versions (showing 12 of 12)

Version Deps Published
8.0.14 34 / 8
8.0.13 31 / 8
8.0.10 31 / 8
8.0.9 31 / 8
6.0.4 14 / 7
6.0.3 11 / 7
6.0.1 7 / 7
3.7.0 5 / 6
3.6.1 5 / 6
1.0.2 3 / 5
1.0.1 3 / 5
1.0.0 3 / 4

v8.0.14

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brianonbased.

v8.0.13

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brianonbased.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.0.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.0.9

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brianonbased.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.0.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.0.3

8 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brianonbased.

HIGH Long encoded string in modified file: dist/cli.js source-diff

Modified file contains 6 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: dist/http-server.js source-diff

Modified file contains 6 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: dist/index.js source-diff

Modified file contains 6 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: dist/cli.mjs source-diff

Modified file contains 6 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: dist/http-server.mjs source-diff

Modified file contains 6 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: dist/index.mjs source-diff

Modified file contains 6 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.0.1

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brianonbased.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.7.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.6.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.