MarketNow Registry / Security / eslint-plugin-mcp-security

eslint-plugin-mcp-security

ESLint security rules for Model Context Protocol (MCP) servers — catches SANDWORM_MODE credential harvesting, path traversal, command injection, and CVE patterns at dev time

MarketNow trust score 60/100 Security v0.2.5 by GitHub Actions
Trust score
60/100
Install risk
Runs registry code
Downloads / week
6
Source
npm-registry
Indexed
2026-09-10

Install

$ npx -y eslint-plugin-mcp-security

Installing via npx/uvx/npm install executes arbitrary code from the public registry on your machine. This is the install-risk semantic of the MarketNow catalog — verify the publisher before running it.

Adoption evidence: 6 weekly registry downloads.

How MarketNow scored this

Sentinel Index Heuristics — a security-first estimate from public signals:

Heuristic, not a guarantee. For verified agent credentials and revocation, see the MarketNow Trust API.

What is eslint-plugin-mcp-security?

ESLint security rules for Model Context Protocol (MCP) servers — catches SANDWORM_MODE credential harvesting, path traversal, command injection, and CVE patterns at dev time Indexed by MarketNow with trust 60/100 (Runs registry code).

How do I install it?

Run $ npx -y eslint-plugin-mcp-security Installing via npx/uvx/npm install executes arbitrary code from the public registry on your machine. This is the install-risk semantic of the MarketNow catalog — verify the publisher before running it.

What does the trust score mean?

Security-first heuristic over public signals (age, adoption, typosquat distance, injection markers). It is not a popularity ranking and not a guarantee of safety. eslint-plugin-mcp-security scores 60/100.