Code execution
Shell input, executable selection, and dynamic evaluation.
Uleravo turns MCP server code and local scan reports into redacted, reviewable security evidence. Scan locally, run it in GitHub Actions, or explore a JSON report privately in your browser. Skills, Plugins, and harness permission deltas are next—not current production coverage.
Apache-2.0 core. No account or API key. Node.js 22.13 or newer. Founding pilot details.
npm install -g ./uleravo-0.6.3.tgzuleravo scan ./path-to-mcp-serverFocused by design
Each finding includes a stable fingerprint, source location, redacted evidence, confidence, remediation, and defensible CWE, OWASP, or MITRE ATLAS mappings.
Shell input, executable selection, and dynamic evaluation.
Filesystem paths, outbound destinations, and unsafe transport.
Credentials, mutable packages, and whole-environment forwarding.
Suspicious instructions and undeclared destructive behavior.
The scanner does not import target code, run package scripts, contact discovered URLs, or invoke Git.
JSON, SARIF, comparison, and signed-report workflows preserve evidence before an enforcement decision is made.
Unreadable inputs, safety limits, unresolved LFS pointers, and analysis failures cannot silently become a clean result.
Clear product boundary
Today's analyzer finds 12 focused risk patterns in MCP implementations. The browser explorer reads an existing Uleravo report; it does not rescan source. Skills and Plugins inventory plus Codex harness permissions are unreleased development work.
Uleravo does not yet observe runtime behavior or provide a security enforcement boundary. Static analysis is not certification, and report files should still be treated as sensitive even though the private explorer keeps them in your tab.
Start free, improve with users
Use it today on your own machine or CI runner.
Hands-on rollout while measured use determines whether and how a hosted team layer should be built.
Applications are open. Work begins only after a signed scope and data-handling agreement; there is no self-serve checkout.
Continuous releases
The public CLI and GitHub Action scan MCP code without executing it. The private browser explorer turns a local JSON report into a reviewable view without uploading the report.
Snapshot Agent Skills and Plugins, inspect one defined Codex configuration harness, normalize declared and effective capabilities, and show meaningful permission changes between versions. This work is in development, not released coverage.
Add opt-in runtime observation, shared policy, approvals, audit history, alerts, and integrations after the required tenant-isolation, retention, and incident-response controls are in place.
Release integrity
SHA-256 for uleravo-0.6.3.tgz · 144,768 bytes
Download checksum filef99c30a2f38487693ddf35e72bf6ace01210538de1f3c534ff965e057e3081f0