@lightsparkdev/grid-mcp
The official MCP Server for the Lightspark Grid API
2
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
jeremyatlightsparkcoreymartinmgorven.ls
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:env-spread | AI (semgrep): Intentional pattern: merging upstream client envs into Deno subprocess for MCP server context propagation. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Standard Basic auth header parsing; not obfuscation. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Fires on data-URI base64 construction, not arbitrary module loading. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Reflect.get used in a Proxy for API access tracking, not evasion. | ai | |
| phantom-deps | phantom-dep:ajv | AI (phantom-deps): Declared dep used via config/convention, not direct import. | ai | |
| phantom-deps | phantom-dep:cors | AI (phantom-deps): Declared dep used via config/convention, not direct import. | ai | |
| phantom-deps | phantom-dep:hono | AI (phantom-deps): Declared dep used via config/convention, not direct import. | ai | |
| phantom-deps | phantom-dep:jq-web | AI (phantom-deps): Declared dep used via config/convention, not direct import. | ai | |
| phantom-deps | phantom-dep:cookie-parser | AI (phantom-deps): Declared dep used via config/convention, not direct import. | ai | |
| phantom-deps | phantom-dep:@hono/node-server | AI (phantom-deps): Declared dep used via config/convention, not direct import. | ai | |
| phantom-deps | phantom-dep:zod-to-json-schema | AI (phantom-deps): Declared dep used via config/convention, not direct import. | ai | |
| phantom-deps | phantom-dep:@cloudflare/cabidela | AI (phantom-deps): Framework-scoped package loaded by convention. | ai | |
| phantom-deps | phantom-dep:zod-validation-error | AI (phantom-deps): Declared dep used via config/convention, not direct import. | ai |