@lexbuild/mcp
Model Context Protocol server for LexBuild. Exposes U.S. legal sources to AI agents.
9
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
chris-c-thomas
Keywords
lexbuildmcpmodel-context-protocollegal-techlawragllmai-agentsus-codecfrfederal-register
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): Missing gitHead is a side effect of the CI/CD pipeline change. SLSA provenance attestation provides a stronger cryptographic link to source than gitHead. | ai | |
| provenance | publisher-changed | AI (provenance): Publisher changed to GitHub Actions with SLSA provenance attestation from the same repo. This reflects a legitimate one-time migration to automated CI/CD publishing, not a compromise. | ai | |
| typosquat | typosquat.levenshtein:yup | AI (typosquat): @lexbuild/mcp is a scoped MCP server for legal tech; the Levenshtein match against 'yup' is a spurious false positive with no plausible impersonation intent. | ai |