ToolProof Trust Profile

ai-smithery-jmoak-chrono-mcp

High-impact capability. Restrict to sandbox/test resources and avoid production credentials.

100risk score
Connect With Limitsconnection signal
sensitive_contextrisk type
57evidence score
Source: https://github.com/JMoak/chrono-mcp
Registry: ai.smithery/JMoak-chrono-mcp 0.2.0

Connection signal

High-impact capability. Restrict to sandbox/test resources and avoid production credentials.

Observed tools

  • None observed in this static profile.

Top findings

  • Install risk pattern: unpinned_dependency — package-lock.json:11
  • Install/config context pattern: environment_access — package.json:44
  • Configuration environment variable access — src/cli.ts:9

Recommended controls

  • Install in a sandbox before team or production use.
  • Pin the exact package/repository version.
  • Review install scripts, Dockerfile behavior, and dependency pins.
  • Do not use production credentials during first install.
  • Restrict filesystem, repository, cloud, and database scope.
  • Require human approval for destructive actions.