ToolProof Trust Profile

ai-smithery-kkjdaniel-bgg-mcp

Low observed static risk. Sandbox Only, not production approval.

3risk score
Sandbox Onlyconnection signal
install_chainrisk type
43evidence score
Source: https://github.com/kkjdaniel/bgg-mcp
Registry: ai.smithery/kkjdaniel-bgg-mcp 1.3.2

Connection signal

Low observed static risk. Sandbox Only, not production approval.

Observed tools

  • None observed in this static profile.

Top findings

  • References credential or secret pattern: API_KEY_GENERIC — server.json:20

Recommended controls

  • Install in a sandbox before team or production use.
  • Pin the exact package/repository version.
  • Review install scripts, Dockerfile behavior, and dependency pins.