← Home

@powerhousedao/reactor-mcp

MCP server for document model operations in the Powerhouse ecosystem. For document model creation tasks, consider using the document-model-creator agent which provides a more guided experience.

15
Versions
AGPL-3.0-only
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

acaldas.powerhousememo.devryanwolhuterprometheus-phph-thegoldenmulecallme-tfroidliberuum

Keywords

powerhousevetradocument-modellocal-firstevent-sourcingmcpmodel-context-protocolaiclaudecursorreactor

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:document-drive AI (dependencies): document-drive is a first-party Powerhouse monorepo dependency, pinned to the same version as this package (5.0.0). Not a third-party risk. ai
license copyleft-license:AGPL-3.0-only AI (license): AGPL-3.0-only is the declared license for the entire Powerhouse ecosystem; this is a licensing concern, not a security issue. ai
phantom-deps phantom-dep:@openfeature/core AI (phantom-deps): @openfeature/core is a peer/transitive dep referenced in config; phantom finding is a stable false positive for this package. ai
phantom-deps phantom-dep:@powerhousedao/config AI (phantom-deps): Same-org internal package used indirectly; phantom finding is a stable false positive for this Powerhouse monorepo package. ai
phantom-deps phantom-dep:@powerhousedao/codegen AI (phantom-deps): Same-org internal package used indirectly; phantom finding is a stable false positive for this Powerhouse monorepo package. ai

Versions (showing 15 of 15)

Version Deps Published
6.2.1 10 / 4
6.2.0 10 / 4
6.1.0 10 / 4
6.0.0 10 / 4
5.3.6 14 / 3
5.3.5 14 / 3
5.3.2 14 / 3
5.3.0 14 / 3
5.0.12 14 / 3
5.0.10 14 / 3
5.0.9 14 / 3
5.0.8 14 / 3
5.0.5 14 / 3
5.0.1 14 / 3
5.0.0 14 / 3

v6.2.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.