@froggychips/mcp-vault

security MCP Server

Deterministic registry + supply-chain integrity scanner for MCP (Model Context Protocol) servers. One-line install via npx, hash-pinned 112-entry DB, 4 advisory feeds, offline-first audit. Make MCP boring.

VerifiedInstall Ready
securitysecurity
2 views0 stars0 forksv0.10.0MIT

Why This Matters

Discovered via github-topic:mcp-server and last synced 3mo ago.

VerifiedInstall Ready
Source
github-topic:mcp-server
Stars
0
Last synced
3mo ago
Install
Instructions detected

Install

1. Install the package

npx @froggychips/mcp-vault

2. Add to claude_desktop_config.json

{
  "mcpServers": {
    "-froggychips-mcp-vault": {
      "command": "npx",
      "args": [
        "@froggychips/mcp-vault"
      ]
    }
  }
}

Config file location: ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) / %APPDATA%\Claude\claude_desktop_config.json (Windows)

24
Tools
0
Resources
0
Prompts
Standard I/O
Transport

Available Tools (24)

gh

`gh search repos --topic mcp-server / modelcontextprotocol`

Core

recommend by default

Purpose

Status

Source

Endpoint

20

10

readme

`modelcontextprotocol/servers` README

Score

Tier

Flag

Effect

scope

global install of a typically project-scoped category (`vcs`/`ci-cd`/`pm`/`infra`)

varies

none. Ever.

drift

installed version differs from DB-pinned version

Ecosystem

Integrity

heavy-unbounded

`est_tools_count > 15` (or unknown) and no `--toolsets`/`--caps`/`allowedTools`/`enabledMcpjsonServers` scoping

npm

`npm search mcp-server`

Recommended

recommend with note

project_urls

n/a

unknown

installed but not in DB (legitimate custom servers ok — informational)

Finding

Trigger

untrusted

DB `trust: "candidate"` but actively installed

Deprecated

hide unless asked

Feature

Status

Without

With

Experimental

mention only on ask

search

infra