The Microsoft OSS MCP server exposes tools to discover & validate trusted Microsoft OSS Packages.
Inferred from the transports this listing declares (stdio). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
This entry has been scanned, but the run carries no source-extraction result — either it predates tool-surface extraction or it failed before reaching that stage. A rescan is what would fill this in; the blank says nothing about the package.
The Microsoft OSS MCP server exposes tools to discover & validate trusted Microsoft OSS Packages.
The last scan of this package failed, so no dependency tree was resolved.