← Home

@revealui/mcp

Model Context Protocol integrations for RevealUI — adapter framework, hypervisor, and MCP contracts

22
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

revealui-org

Keywords

revealuimcpmodel-context-protocolaitool-discoveryservers

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:env-spread AI (semgrep): env passed to spawned MCP child process, standard subprocess launch pattern; not remote exfil. ai
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI/CD with SLSA attestation; provenance improved, benign for this org. ai
publish-pattern new-deps-added AI (publish-pattern): New deps are all @revealui/* first-party packages, consistent with monorepo expansion. ai
dependencies unvetted-dep:@revealui/knowledge-graph AI (dependencies): First-party sibling package in same monorepo/org, not an unrelated third-party dep. ai
source-diff source-size-tripled AI (source-diff): Growth driven by generated .d.ts contracts file and added first-party features, not obfuscated payload. ai
provenance no-provenance AI (provenance): Lack of Sigstore provenance is common (~88% of npm packages) and not a disqualifier for this package's risk profile. ai
phantom-deps phantom-dep:dotenv AI (phantom-deps): dotenv is declared in package.json dependencies and used in config files; false positive common in configuration-heavy packages. ai
typosquat typosquat.levenshtein:yup AI (typosquat): Scoped @revealui package with clear identity, GitHub repo, and commercial homepage. No plausible impersonation of 'yup'; edit distance of 2 is coincidental. ai
dependencies unvetted-dep:@revealui/contracts AI (dependencies): First-party monorepo dependency from the same @revealui org; not a third-party risk. ai
dependencies unvetted-dep:@revealui/config AI (dependencies): First-party monorepo dependency from the same @revealui org; not a third-party risk. ai
dependencies unvetted-dep:@revealui/core AI (dependencies): First-party monorepo dependency from the same @revealui org; not a third-party risk. ai

Versions (showing 22 of 22)

Version Deps Published
0.8.3 10 / 5
0.8.2 10 / 5
0.8.1 10 / 4
0.8.0 10 / 4
0.7.1 9 / 4
0.7.0 7 / 4
0.6.2 7 / 4
0.6.1 7 / 4
0.6.0 7 / 4
0.5.0 7 / 4
0.4.0 7 / 4
0.3.0 7 / 4
0.2.0 7 / 4
0.1.11 6 / 4
0.1.10 6 / 4
0.1.9 6 / 4
0.1.8 5 / 4
0.1.7 5 / 4
0.1.5 5 / 4
0.1.3 5 / 4
0.1.1 5 / 4
0.1.0 6 / 4

v0.8.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.1

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: revealui-org → GitHub Actions (on 2026-07-16, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (revealui-org) on 2026-07-16, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.7.0

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: revealui-org → GitHub Actions (on 2026-06-22, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (revealui-org) on 2026-06-22, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.4.0

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: revealui-org → GitHub Actions (on 2026-05-16, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (revealui-org) on 2026-05-16, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.3.0

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: revealui-org → GitHub Actions (on 2026-05-16, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (revealui-org) on 2026-05-16, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.