中文 · English

← Evidence index

github.com/greglas75/codesift

incomplete Threshold medium · generated 2026-09-22T12:17:45.087Z

Publisher: greglas75

Packages: codesift-mcp@0.17.0 (npm)
Repository: https://github.com/greglas75/codesift

How this record was produced

The inputs are public: the registry record and the manifest of the package that was actually published. Each finding below includes its file and rule.

Repository source is outside this index’s scan scope. Use the CLI locally for source scanning; source code does not need to leave your machine.

A finding is a matched shape, not a conclusion. It does not by itself prove exploitability or intent. Findings below the configured threshold do not change the verdict. Unmeasured work is listed separately; unmeasured does not mean clean.

repositoryMetadata

status=clean · source=github-census

This block produced no findings.

packageManifest

status=findings · source=package-registry

RuleSeverityLocationDescription
install-time-executionhighscripts.postinstall="node ./dist/cli.js setup all 2>/dev/null && echo '\n ✨ CodeSift MCP installed and configured for all platforms.\n ⚠️ Restart your AI client (Cmd+Q for Claude Code) to load new MCP server.\n' || echo '\n ✨ CodeSift MCP installed. Run: codesift setup all\n'; node ./dist/install-check.js 2>/dev/null || true"
install-hook-script-inspectedinfohook runs ./dist/cli.js (5438 bytes): no fetch/spawn/decode pattern found

Unmeasured work

This record has no unmeasured blocks.

Scan coverage

State: incomplete · required 3, completed 2, failed 1

ScannerRequiredStatusOutputConsistencyReason
repositoryMetadataRequiredcompletedPresent / parseableok
packageManifestRequiredcompletedPresent / parseableok
repositorySourceRequiredskippedAbsent / not parseableunverifiedsource-not-read

Machine-readable record

JSON:
https://xn--5kvo87g.com/v1/servers/github.com%2Fgreglas75%2Fcodesift

README badge:
https://xn--5kvo87g.com/badge/github.com%2Fgreglas75%2Fcodesift.svg