About this integration
Pre-install security scanner for AI agent skills (local stdio MCP). Offline static scan; no upload.
- Transport
- stdio
- Authentication
- none
- Initial setup
- none
- Runtime
- unattended
- Evidence
- documented
- Version
- 0.4.2
- Package
- @yottameta/yotta-verify-mcp
- Last compatibility test
- Not independently tested
Connect your agent
@yottameta/yotta-verify-mcpPublisher README and executable npm manifest reviewed at their captured hashes. The package and scanned targets were not installed or executed, and the documentation is not an independent security audit.
Capabilities: Static skill and package scanning, Verification reports, CI severity gates, Audit badge generation
Connected profiles
Additional details
io.github.YottaMeta/yotta-verify-mcp
Source ↗ · Checked 2026-09-170.4.2
Source ↗ · Checked 2026-09-17CC0-1.0; package licenses are separate
Source ↗ · Checked 2026-09-17npm
Source ↗ · Checked 2026-09-17@yottameta/yotta-verify-mcp
Source ↗ · Checked 2026-09-200.4.3
Source ↗ · Checked 2026-09-20The publisher documents a standard stdio MCP server that an MCP client launches with the npm command; directory scans are local and offline, and the reviewed package was not executed.
Source ↗ · Checked 2026-09-20No service credential is documented for the local scanner. Directory scans make no network calls; scanning a named npm package may download that public package before performing the local static scan.
Source ↗ · Checked 2026-09-20Configure the MCP client to launch `npx -y @yottameta/yotta-verify-mcp` over stdio.
Source ↗ · Checked 2026-09-20Publisher documentation reviewed; package and integration endpoint not executed or independently security-audited.
Source ↗ · Checked 2026-09-20