ai-smithery-jmoak-chrono-mcp
High-impact capability. Restrict to sandbox/test resources and avoid production credentials.
Source: https://github.com/JMoak/chrono-mcp
Registry: ai.smithery/JMoak-chrono-mcp 0.2.0
Registry: ai.smithery/JMoak-chrono-mcp 0.2.0
Connection signal
High-impact capability. Restrict to sandbox/test resources and avoid production credentials.
Observed tools
- None observed in this static profile.
Top findings
- Install risk pattern: unpinned_dependency — package-lock.json:11
- Install/config context pattern: environment_access — package.json:44
- Configuration environment variable access — src/cli.ts:9
Recommended controls
- Install in a sandbox before team or production use.
- Pin the exact package/repository version.
- Review install scripts, Dockerfile behavior, and dependency pins.
- Do not use production credentials during first install.
- Restrict filesystem, repository, cloud, and database scope.
- Require human approval for destructive actions.