@intlayer/mcp
Intlayer MCP server. Handle MCP to help IDE to use Intlayer. It build, fill, pull, push, dictionaries
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/esm/installSkills-Bzx_k5dj.mjs | AI (source-diff): Minified build artifact, readable logic, no obfuscation signature. | ai | |
| source-diff | obfuscated-file:dist/esm/installSkills-fT8EtlY8.mjs | AI (source-diff): Minified bundle output implementing local asset resolution logic; benign. | ai | |
| source-diff | obfuscated-file:dist/esm/cli-C5nRaDjk.mjs | AI (source-diff): tsdown/bun minified build output, not true obfuscation; no malicious behavior in sample. | ai | |
| source-diff | obfuscated-file:dist/esm/packages/@intlayer/chokidar/dist/esm/installSkills/index.mjs | AI (source-diff): Minified bundler output implementing a documented skills-installer, not true obfuscation or malicious behavior. | ai | |
| phantom-deps | phantom-dep:@intlayer/cli | AI (phantom-deps): Same-org sibling package, false positive. | ai | |
| phantom-deps | phantom-dep:@intlayer/docs | AI (phantom-deps): Same-org sibling package, false positive. | ai | |
| phantom-deps | phantom-dep:@intlayer/types | AI (phantom-deps): Same-org sibling package, false positive. | ai | |
| phantom-deps | phantom-dep:@intlayer/config | AI (phantom-deps): Same-org sibling package, false positive. | ai | |
| phantom-deps | phantom-dep:@intlayer/api | AI (phantom-deps): Same-org sibling package, false positive. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): Referenced via config, common monorepo pattern. | ai | |
| phantom-deps | phantom-dep:express | AI (phantom-deps): Referenced via config, common monorepo pattern. | ai | |
| phantom-deps | phantom-dep:dotenv | AI (phantom-deps): Referenced via config, common monorepo pattern. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are same-org sibling packages at matching version, not third-party additions. | ai | |
| provenance | missing-githead | AI (provenance): Monorepo publish pipeline quirk, no malicious behavior; consistent across sibling packages. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Monorepo bundling of sibling packages (cli/docs) into dist, not injected code. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Bundled dependency sources inflate size; consistent with monorepo dist structure. | ai | |
| dependencies | unvetted-dep:@intlayer/engine | AI (dependencies): First-party sibling package in same monorepo/publisher scope. | ai | |
| typosquat | typosquat.levenshtein:yup | AI (typosquat): Scoped @intlayer/* package in an established monorepo; Levenshtein match to 'yup' is a false positive. | ai | |
| dependencies | unvetted-dep:@intlayer/docs | AI (dependencies): First-party monorepo sibling dependency, same version pin. | ai | |
| dependencies | unvetted-dep:@intlayer/cli | AI (dependencies): First-party monorepo sibling dependency, same version pin. | ai | |
| dependencies | unvetted-dep:@intlayer/api | AI (dependencies): First-party monorepo sibling dependency, same version pin. | ai | |
| dependencies | unvetted-dep:@intlayer/chokidar | AI (dependencies): First-party monorepo sibling dependency, same version pin. | ai |
Versions (showing 38 of 138)
| Version | Deps | Published |
|---|---|---|
| 7.5.2 | 8 / 11 | |
| 7.5.1 | 8 / 11 | |
| 7.5.0 | 8 / 11 | |
| 7.4.0 | 8 / 11 | |
| 7.3.15 | 8 / 11 | |
| 7.3.14 | 8 / 11 | |
| 7.3.13 | 8 / 11 | |
| 7.3.12 | 8 / 11 | |
| 7.3.11 | 8 / 11 | |
| 7.3.10 | 8 / 11 | |
| 7.3.9 | 8 / 11 | |
| 7.3.8 | 8 / 11 | |
| 7.3.7 | 8 / 11 | |
| 7.3.6 | 8 / 11 | |
| 7.3.5 | 8 / 11 | |
| 7.3.4 | 8 / 11 | |
| 7.3.3 | 8 / 11 | |
| 7.3.2 | 8 / 11 | |
| 7.3.1 | 8 / 11 | |
| 7.3.0 | 8 / 11 | |
| 7.2.3 | 8 / 11 | |
| 7.2.2 | 8 / 11 | |
| 7.2.0 | 8 / 11 | |
| 7.1.9 | 8 / 11 | |
| 7.1.8 | 8 / 11 | |
| 7.1.7 | 8 / 11 | |
| 7.1.6 | 8 / 11 | |
| 7.1.5 | 8 / 11 | |
| 7.1.4 | 8 / 11 | |
| 7.1.3 | 8 / 11 | |
| 7.1.2 | 8 / 11 | |
| 7.1.1 | 8 / 11 | |
| 7.1.0 | 8 / 10 | |
| 7.0.8 | 8 / 10 | |
| 7.0.7 | 8 / 10 | |
| 7.0.6 | 8 / 10 | |
| 7.0.5 | 8 / 10 | |
| 7.0.4 | 8 / 10 |
v7.1.4
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ay.pineau.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.1.3
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ay.pineau.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.1.2
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ay.pineau.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.1.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ay.pineau.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.1.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ay.pineau.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.