ai-kawacode-mcp
Do not install from this profile alone. High-impact signals or incomplete controls/evidence require manual review.
Source: https://github.com/kawacode-ai/kawa.mcp
Registry: ai.kawacode/mcp 6.1.5
Registry: ai.kawacode/mcp 6.1.5
Connection signal
Do not install from this profile alone. High-impact signals or incomplete controls/evidence require manual review.
Observed tools
- None observed in this static profile.
Top findings
- Detected capability: shell_execution — src/tools/resolve-origin.ts:1
- Detected capability: wallet_payment — deploy.sh:36
- Detected capability: filesystem_write_delete — deploy.sh:79
Recommended controls
- Install in a sandbox before team or production use.
- Pin the exact package/repository version.
- Review install scripts, Dockerfile behavior, and dependency pins.
- Do not use production credentials during first install.
- Restrict filesystem, repository, cloud, and database scope.
- Require human approval for destructive actions.