ai.takara/miru
findings Threshold medium · generated 2026-10-06T08:17:49.441Z
Publisher: takara-ai
Packages: @takara-ai/miru-code@1.10.1 (npm)
Repository: https://github.com/takara-ai/miru-code
How this record was produced
The inputs are public: the registry record and the manifest of the package that was actually published. Each finding below includes its file and rule.
Repository source is outside this index’s scan scope. Use the CLI locally for source scanning; source code does not need to leave your machine.
A finding is a matched shape, not a conclusion. It does not by itself prove exploitability or intent. Findings below the configured threshold do not change the verdict. Unmeasured work is listed separately; unmeasured does not mean clean.
registryDocument
status=findings · source=mcp-census
| Rule | Severity | Location | Description |
|---|---|---|---|
| stdio-transport | info | packages[].transport.type=stdio (runs locally as a child process) |
packageManifest
status=findings · source=guard-scan
| Rule | Severity | Location | Description |
|---|---|---|---|
| AG-SUPPLY-001 | medium | package.json | devDependencies entry tree-sitter-vue resolves to a mutable source: github:tree-sitter-grammars/tree-sitter-vue#ce8011a (dev-only: cannot reach a consumer of this package) |
| AG-SUPPLY-001 | medium | package.json | devDependencies entry tree-sitter-astro resolves to a mutable source: github:virchau13/tree-sitter-astro#213f6e6 (dev-only: cannot reach a consumer of this package) |
Unmeasured work
This record has no unmeasured blocks.
Scan coverage
State: complete · required 2, completed 2, failed 0
| Scanner | Required | Status | Output | Consistency | Reason |
|---|---|---|---|---|---|
| registryDocument | Required | completed | Present / parseable | ok | |
| packageManifest | Required | completed | Present / parseable | ok |
Machine-readable record
JSON:https://xn--5kvo87g.com/v1/servers/ai.takara%2Fmiru
README badge:https://xn--5kvo87g.com/badge/ai.takara%2Fmiru.svg