{"name":"io.github.AbduljabbarBXR/reference-mcp","slug":"abduljabbarbxr-reference-mcp","title":"reference-mcp","description":"Reference integrity for AI agents. Scans and verifies links, imports, assets, deps.","url":"https://mcp.market/server/abduljabbarbxr-reference-mcp","rating":null,"grade":"D","score":46,"certified":false,"status":"active","category":"other","tags":[],"presence":{"score":14,"stars":null,"forks":null,"downloads_week":580,"last_push_at":null,"license":"MIT"},"uptime":null,"claimed":false,"transport":"npm","callable_via_gateway":false,"default_price_micros":0,"repository":null,"website":null,"version":"0.1.6","remotes":[],"packages":[{"registryType":"npm","identifier":"reference-mcp","version":"0.1.6","transport":{"type":"stdio"}}],"tools":[{"name":"reference.check","description":"Verify the references in a repository. Local paths are checked against the filesystem, module names against the npm registry, and URLs over HTTP. Returns findings with a status per reference.","write_action":false,"price_micros":0,"input_schema":null},{"name":"reference.scan","description":"Scan a repository and extract every reference: URLs, local imports, assets, and module dependencies. Returns a deduplicated list by kind.","write_action":false,"price_micros":0,"input_schema":null}],"scan":{"score":46,"grade":"D","scanned_at":"2026-09-19T21:32:14.223Z","report":{"scannerVersion":"0.1.9","scannedAt":"2026-09-19T21:32:14.225Z","components":{"code":{"score":13,"max":25,"notes":["2 source files scanned"]},"reliability":{"score":-1,"max":20,"notes":["no gateway calls yet and no remote to probe"]},"poisoning":{"score":-1,"max":15,"notes":["tools not inspected (local package is not executed); not counted"]},"auth":{"score":12,"max":15,"notes":["local package, no credentials required"]},"maintenance":{"score":3,"max":15,"notes":["no repository listed"]},"identity":{"score":2,"max":10,"notes":["no repository or website to verify"]}},"findings":[{"id":"exec.shell-concat","severity":"high","component":"code","title":"Shell command built from a string (injection risk)","evidence":"src/index.js: …lse { try { const match = execSync(`find \"${root}\" -type f -name \"${basenameName(value)}\" 2>/dev/null | head…"},{"id":"maint.no-repo","severity":"low","component":"maintenance","title":"No source repository listed"}],"inputs":{"packages":[{"registryType":"npm","identifier":"reference-mcp","version":"0.1.6","found":true,"license":"MIT","hasInstallScripts":false,"dependencyCount":1,"publishedAt":"2026-09-17T17:16:08.067Z","weeklyDownloads":580}],"repo":{"found":false},"icon":{"url":null,"source":"none"},"presence":{"stars":null,"forks":null,"downloadsWeek":580,"license":"MIT","lastPushAt":null,"score":14}}}},"grade_history":[{"kind":"downgrade","fromGrade":"C","toGrade":"D","reason":"score 46: Shell command built from a string (injection risk); No source repository listed","createdAt":"2026-09-19T00:30:07.511Z"}],"reviews":[]}