Statically audits MCP tool surfaces for token cost, schema quality, and design issues.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts — it cannot prove the absence of malicious code.
Statically audits MCP tool surfaces for token cost, schema quality, and design issues.