@llui/mcp
LLui MCP server — LLM debug tools via Model Context Protocol
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@llui/security | AI (dependencies): First-party @llui scoped package from same monorepo/publisher. | ai | |
| provenance | missing-githead | AI (provenance): Consistent publisher with 482 approved packages; minor CI metadata gap, no behavior change. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New dep is first-party @llui sibling package, not an unvetted third party. | ai | |
| dependencies | unvetted-dep:@llui/notes-format | AI (dependencies): First-party sibling package in the same llui monorepo/org. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): Localhost 127.0.0.1 binding message for local debug server, not remote exfil. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): Scoped dynamic-import shim to avoid bundler resolving optional peer dep. | ai | |
| typosquat | typosquat.levenshtein:yup | AI (typosquat): Scoped package @llui/mcp is not a typosquat of yup; Levenshtein match is coincidental across different namespaces. | ai | |
| phantom-deps | phantom-dep:@llui/eslint-plugin | AI (phantom-deps): Same-org eslint plugin used for linting, not imported at runtime; stable false positive for this package. | ai |
Versions (showing 81 of 81)
| Version | Deps | Published |
|---|---|---|
| 0.14.0 | 7 / 4 | |
| 0.13.4 | 7 / 4 | |
| 0.13.3 | 6 / 4 | |
| 0.13.2 | 5 / 4 | |
| 0.13.1 | 7 / 4 | |
| 0.13.0 | 7 / 4 | |
| 0.12.6 | 7 / 4 | |
| 0.12.5 | 7 / 4 | |
| 0.12.4 | 7 / 4 | |
| 0.12.3 | 7 / 4 | |
| 0.12.2 | 7 / 4 | |
| 0.12.1 | 7 / 4 | |
| 0.12.0 | 7 / 4 | |
| 0.11.0 | 7 / 4 | |
| 0.10.0 | 7 / 4 | |
| 0.9.0 | 7 / 4 | |
| 0.8.0 | 7 / 4 | |
| 0.7.0 | 7 / 4 | |
| 0.6.4 | 7 / 4 | |
| 0.6.3 | 7 / 4 | |
| 0.6.2 | 7 / 4 | |
| 0.6.1 | 7 / 4 | |
| 0.6.0 | 7 / 4 | |
| 0.5.16 | 7 / 4 | |
| 0.5.14 | 7 / 4 | |
| 0.5.13 | 7 / 4 | |
| 0.5.12 | 7 / 4 | |
| 0.5.11 | 7 / 4 | |
| 0.5.10 | 7 / 4 | |
| 0.5.9 | 7 / 4 | |
| 0.5.8 | 7 / 4 | |
| 0.5.7 | 7 / 4 | |
| 0.5.6 | 6 / 4 | |
| 0.5.5 | 6 / 4 | |
| 0.5.4 | 6 / 4 | |
| 0.5.3 | 6 / 4 | |
| 0.5.2 | 6 / 4 | |
| 0.5.1 | 6 / 4 | |
| 0.5.0 | 6 / 4 | |
| 0.4.0 | 6 / 4 | |
| 0.3.2 | 6 / 4 | |
| 0.3.1 | 6 / 4 | |
| 0.3.0 | 6 / 4 | |
| 0.2.0 | 4 / 4 | |
| 0.1.0 | 4 / 4 | |
| 0.0.37 | 4 / 4 | |
| 0.0.36 | 4 / 4 | |
| 0.0.35 | 4 / 4 | |
| 0.0.34 | 4 / 4 | |
| 0.0.33 | 4 / 4 | |
| 0.0.32 | 4 / 4 | |
| 0.0.31 | 4 / 4 | |
| 0.0.30 | 4 / 4 | |
| 0.0.29 | 4 / 4 | |
| 0.0.28 | 4 / 4 | |
| 0.0.27 | 4 / 4 | |
| 0.0.25 | 3 / 4 | |
| 0.0.24 | 4 / 3 | |
| 0.0.23 | 4 / 2 | |
| 0.0.22 | 4 / 2 | |
| 0.0.21 | 4 / 2 | |
| 0.0.20 | 4 / 2 | |
| 0.0.19 | 4 / 2 | |
| 0.0.18 | 4 / 2 | |
| 0.0.17 | 4 / 2 | |
| 0.0.16 | 4 / 2 | |
| 0.0.15 | 3 / 2 | |
| 0.0.14 | 3 / 2 | |
| 0.0.13 | 3 / 2 | |
| 0.0.12 | 3 / 2 | |
| 0.0.11 | 3 / 2 | |
| 0.0.10 | 3 / 2 | |
| 0.0.9 | 3 / 2 | |
| 0.0.8 | 3 / 2 | |
| 0.0.7 | 3 / 2 | |
| 0.0.6 | 2 / 2 | |
| 0.0.5 | 2 / 2 | |
| 0.0.4 | 2 / 2 | |
| 0.0.3 | 2 / 2 | |
| 0.0.2 | 2 / 2 | |
| 0.0.1 | 2 / 2 |
v0.14.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.13.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.13.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.13.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.35
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: fponticelli.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.34
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: fponticelli.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.33
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: fponticelli.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.32
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: fponticelli.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.31
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: fponticelli.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.30
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: fponticelli.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.28
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: fponticelli.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.27
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: fponticelli.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.25
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: fponticelli.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.24
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: fponticelli.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.22
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: fponticelli.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.21
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: fponticelli.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.19
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: fponticelli.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.16
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: fponticelli.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.15
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: fponticelli.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.14
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: fponticelli.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.10
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: fponticelli.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.7
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: fponticelli.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.