ai-meetsquad-squad
High-impact capability. Restrict to sandbox/test resources and avoid production credentials.
Source: https://github.com/the-basilisk-ai/squad-mcp
Registry: ai.meetsquad/squad 3.0.1
Registry: ai.meetsquad/squad 3.0.1
Connection signal
High-impact capability. Restrict to sandbox/test resources and avoid production credentials.
Observed tools
- None observed in this static profile.
Top findings
- Broad or write-capable OAuth/API scope: github_write_scope — flake.lock:11
- Detected capability: filesystem_write_delete — scripts/openapi-client-esm-fix.ts:17
- Detected capability: environment_access — src/helpers/mintToken.ts:25
Recommended controls
- Install in a sandbox before team or production use.
- Pin the exact package/repository version.
- Review install scripts, Dockerfile behavior, and dependency pins.
- Do not use production credentials during first install.
- Restrict filesystem, repository, cloud, and database scope.
- Require human approval for destructive actions.