Skip to content

vinmay/reachscan

v0.1.0Apache-2.0

Vet an MCP server before you install it: see what each tool can execute, read, write, and send, using reachscan's static reachability analysis.

What this package declares

The file a client reads when it loads this plugin, exactly as this revision carries it.

plugin.json
{
  "$schema": "https://agent-plugins.org/schemas/1.0.0/plugin.schema.json",
  "name": "reachscan",
  "version": "0.1.0",
  "description": "Vet an MCP server before you install it: see what each tool can execute, read, write, and send, using reachscan's static reachability analysis.",
  "author": {
    "name": "Vinmay Nair",
    "url": "https://github.com/vinmay"
  },
  "homepage": "https://github.com/vinmay/reachscan",
  "repository": "https://github.com/vinmay/reachscan",
  "license": "Apache-2.0",
  "keywords": [
    "mcp",
    "security",
    "static-analysis",
    "supply-chain"
  ],
  "extensions": {
    "com.openai": {
      "interface": {
        "displayName": "reachscan",
        "shortDescription": "Vet MCP servers before install",
        "longDescription": "Runs the reachscan CLI on an MCP server (GitHub URL, PyPI package, or local path) and summarizes what each tool can reach: shell execution, file reads and writes, network sends, secrets, dynamic code. Ends with an install, review, or avoid recommendation based only on the scan findings.",
        "developerName": "Vinmay Nair",
        "category": "Developer Tools",
        "capabilities": [
          "Read"
        ],
        "websiteURL": "https://github.com/vinmay/reachscan",
        "defaultPrompt": [
          "Vet this MCP server before I add it: https://github.com/org/some-mcp-server",
          "What can the tools in pypi:some-mcp-package actually do?"
        ],
        "supportURL": "https://github.com/vinmay/reachscan/issues",
        "privacyPolicyURL": "https://github.com/vinmay/reachscan/blob/main/PRIVACY.md",
        "brandColor": "#1F4FD6",
        "composerIcon": "./assets/icon.svg",
        "logo": "./assets/icon.svg"
      }
    }
  }
}

Client extensions

Data this package carries for particular clients. The directory lists the clients named and never reads what is addressed to them.

  • com.openai