@reftrixmcp/mcp-server
MCP Server for Reftrix - AI agent integration for web design analysis, layout extraction, motion detection, and quality evaluation
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:etc-passwd-access | AI (semgrep): Fires on a comment string listing /etc/passwd as an example of path traversal to reject — not actual credential access. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): Fires on a localhost (127.0.0.1) log message, not an outbound request to a raw IP. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Standard HTTP Basic Auth credential parsing in an admin UI handler — expected pattern. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): Spreading process.env to pass PGPASSWORD to a subprocess is the standard pg/psql pattern. | ai | |
| semgrep | semgrep:env-bulk-read | AI (semgrep): Used to merge .env.local into a subprocess environment — legitimate config utility pattern. | ai | |
| phantom-deps | phantom-dep:ws | AI (phantom-deps): ws is a transitive dep used via config; phantom-dep heuristic fires on config-only references. | ai | |
| phantom-deps | phantom-dep:pngjs | AI (phantom-deps): pngjs referenced in config/type context; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:culori | AI (phantom-deps): culori referenced in config; phantom-dep heuristic false positive. | ai |
Versions (showing 6 of 6)
| Version | Deps | Published |
|---|---|---|
| 0.6.0 | 22 / 15 | |
| 0.5.1 | 22 / 15 | |
| 0.2.1 | 21 / 14 | |
| 0.2.0 | 21 / 14 | |
| 0.1.8 | 17 / 13 | |
| 0.1.7 | 17 / 13 |
v0.6.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.