vinmay/reachscan
v0.1.0Apache-2.0
Vet an MCP server before you install it: see what each tool can execute, read, write, and send, using reachscan's static reachability analysis.
What this package declares
The file a client reads when it loads this plugin, exactly as this revision carries it.
plugin.json
{
"$schema": "https://agent-plugins.org/schemas/1.0.0/plugin.schema.json",
"name": "reachscan",
"version": "0.1.0",
"description": "Vet an MCP server before you install it: see what each tool can execute, read, write, and send, using reachscan's static reachability analysis.",
"author": {
"name": "Vinmay Nair",
"url": "https://github.com/vinmay"
},
"homepage": "https://github.com/vinmay/reachscan",
"repository": "https://github.com/vinmay/reachscan",
"license": "Apache-2.0",
"keywords": [
"mcp",
"security",
"static-analysis",
"supply-chain"
],
"extensions": {
"com.openai": {
"interface": {
"displayName": "reachscan",
"shortDescription": "Vet MCP servers before install",
"longDescription": "Runs the reachscan CLI on an MCP server (GitHub URL, PyPI package, or local path) and summarizes what each tool can reach: shell execution, file reads and writes, network sends, secrets, dynamic code. Ends with an install, review, or avoid recommendation based only on the scan findings.",
"developerName": "Vinmay Nair",
"category": "Developer Tools",
"capabilities": [
"Read"
],
"websiteURL": "https://github.com/vinmay/reachscan",
"defaultPrompt": [
"Vet this MCP server before I add it: https://github.com/org/some-mcp-server",
"What can the tools in pypi:some-mcp-package actually do?"
],
"supportURL": "https://github.com/vinmay/reachscan/issues",
"privacyPolicyURL": "https://github.com/vinmay/reachscan/blob/main/PRIVACY.md",
"brandColor": "#1F4FD6",
"composerIcon": "./assets/icon.svg",
"logo": "./assets/icon.svg"
}
}
}
}
Client extensions
Data this package carries for particular clients. The directory lists the clients named and never reads what is addressed to them.
- com.openai