CanopiiCanopiiAll serversEnterprise →
io.github.mohitagw15856/pm-claude-skills

io.github.mohitagw15856/pm-claude-skills v62.0.0

Security Trust Score
Grade D · Weak posture
Tier 1 · Public sourceHigh confidence · 98%
Declared MCP capabilities
ResourcesPrompts

This server scored D. Run it behind runtime policy enforcement so one bad tool call can't become an incident.

2 issues capping this score
  • mediumNo install/post-install scriptsruns postinstall
  • mediumNo over-broad / destructive tools1 over-broad tool(s)
Reputation1.3kstars226forks8.9kdownloads/mo10open issues19d agolast commit<1yage

Security controls

Deterministic, evidence-backed. Score earned from passing controls; a failed guard caps it.

Model–MCP Runtime Guardrails

  • Fail
    User-in-the-Loop / Approval Scopeguard1 over-broad tool(s)

    No over-broad or destructive tools (arbitrary shell, bulk-delete) that warrant human approval. How many servers fail this?

    Diagram a system or technical architecture — services, data

    Fix: Scope tools narrowly; avoid arbitrary command execution and destructive defaults.

  • Warn
    Strict JSON Schema Enforcementschemas not strict

    Tool inputs are constrained (additionalProperties:false), so unexpected arguments can't be smuggled in.

    Fix: Set additionalProperties:false and require explicit parameters on every tool.

  • Pass
    Indirect Prompt Injection (IPI) Defensesguardno injection markers

    Tool/prompt/resource text is free of hidden instructions that could hijack the agent.

  • Pass
    Tool Definition Integrityguardtool definitions stable; no risky changes in version history

    Every consecutive version pair is diffed for new injection markers or destructive scope — a risky diff anywhere in history is a rug-pull (fail, durable); benign description drift warns.

Application Security Checks

  • Fail
    No install/post-install scriptsguardruns postinstall

    install hooks run arbitrary code on every consumer at install time. How many servers fail this?

    Fix: Remove preinstall/install/postinstall scripts, or document and minimize them.

  • Warn
    No path traversalguard3 occurrences

    Naive path checks let tools read/write outside intended directories (EscapeRoute-class).

    web/artifacts.js:230web/export-doc.js:137web/export-doc.js:137

    Fix: Resolve to a canonical path and verify containment; reject ../ and symlinks.

  • Warn
    No SSRF sinksguard5 occurrences

    Fetching tool-supplied URLs can pivot into internal networks and metadata services.

    web/app.js:108web/live.js:10web/live.js:14web/providers.js:244

    Fix: Allow-list destinations; reject arbitrary/loopback/link-local URLs.

  • Warn
    Credentials sourced from environmentno env-based config detected

    Reading secrets from env/secret stores avoids hardcoding them.

    Fix: Read credentials from environment variables or a secret manager.

  • Warn
    Dependencies pinned (lockfile)no lockfile found

    A lockfile makes installs reproducible and resistant to silent dependency swaps.

    Fix: Commit a lockfile (package-lock.json / pnpm-lock.yaml / poetry.lock).

  • Warn
    Established maintainersingle maintainer

    Brand-new / single anonymous maintainers raise takeover and malware risk.

    Fix: Publish under an established account/org; add multiple maintainers.

  • Warn
    Has a security policyno security policy

    A SECURITY.md gives a private path to report vulnerabilities.

    Fix: Add SECURITY.md with a disclosure contact and process.

  • Pass
    No command-injection sinksguardno sinks found

    Untrusted tool input reaching a shell yields remote code execution.

  • Pass
    No dynamic code executionguardno sinks found

    eval()/exec()/Function() on tool-derived strings allows arbitrary code execution.

  • Pass
    No unsafe deserializationguardno sinks found

    pickle/yaml.load/etc. on untrusted data can execute code.

  • Pass
    No committed secretsguardno secrets found

    Hardcoded keys/tokens in published source are live credentials an attacker can use.

  • Pass
    No known-vulnerable dependencies1 runtime deps, no known CVEs

    Runtime dependencies (parsed from the lockfile) are scanned against OSV.dev for published CVEs. Advisory: flagged dependencies lower the score but don't hard-cap it, since transitive reachability is unproven.

  • Pass
    Package name not typosquattingguarddistinct package name

    Names mimicking popular packages are a common malware delivery vector.

  • Pass
    Published with provenancepublished with provenance

    Build provenance attests the artifact was built from the claimed source by CI.

  • Pass
    Actively maintainedrecent commits

    Unmaintained servers don't receive security fixes.

  • Pass
    Repository not archivedguardactive

    Archived repositories will never be patched.

  • Pass
    Declares a licenseMIT

    A clear license is required for legal enterprise use.

  • Pass
    Adoption & popularityestablished adoption

    A small, capped nudge from stars/downloads — widely-used servers get more eyes on bugs. It can never offset a real security failure.

  • Not checked
    Signed releasesnot evaluated

    Signed releases let consumers verify artifacts weren't tampered with.

Transport & Trust Model

  • Warn
    Execution Sandboxingruns natively (no container image)

    A container/sandbox image limits blast radius; a server that runs natively has full host access.

    Fix: Ship a Dockerfile/Containerfile (or document a sandboxed run) so the server runs isolated.

  • Pass
    Network Exposureno bind-all detected

    Binding 0.0.0.0 or exposing debug inspectors widens the attack surface.

  • N/A
    Transport Encryption (TLS)guardno remote endpoints

    Plaintext HTTP exposes traffic and bearer tokens to interception.

  • N/A
    IAM / Authentication Scopingno remote endpoints

    OAuth 2.1 / Protected Resource Metadata gates who can invoke tools.

  • N/A
    Live Endpoint Reachablenot dynamically scanned

    A dynamic scan connected to the declared remote endpoint and it responded — verified live, not a dead URL.

  • N/A
    Authentication Enforced (live)not dynamically scanned

    If the server declares auth is required, it must actually reject anonymous clients. Serving tools to unauthenticated callers is a real exposure.

Tools (42)

Turn a skillSimulate the acquirerAudit whether the organisationConduct a structured ethical review of an AI or ML feature,Design the archive layer that keeps current workspaces leanExtract and risk-rate hidden assumptions in a product briefExtract every hidden assumption from a plan or document andOptimize an article for Answer Engine Optimization (AEO) soWrite a short, punchy announcement designed to be shared asWrite a sincere, effective apology to a customer, group, orAudit a content library, docs site, or blog for AI-generatedBuild a structured account plan for any key customer or targBuild an all-hands that lands with everyone from intern to VCreate an Architecture Decision Record (ADR) for any technicDesign a 360-degree feedback survey or write a structured 36Design an evaluation plan for an LLM or AI feature before shDesign statistically rigorous A/B tests for product featuresGenerate a WCAG 2.2 accessibility audit checklist and remediPrepare for an industry analyst briefing (Gartner, ForresterReview AI-authored code for its characteristic failure modesReview an LLM agent design and find where it will be unreliaRun a blameless postmortem for an incident caused by an AI aSpecify an autonomous or tool-using AI agent before buildingSpecify the tracing, metrics, and alerting for an AI agent oStructure AI and ML product decisions with the rigour of anyStructure vague opportunities and unclear briefs into actionWrite a PRD for an AI-powered feature, covering the things nWrite an API versioning strategy document for a service or AWrite clear, developer-facing API documentation. Use when asWrite platform-native paid ad copy with multiple angles to tDiagram a system or technical architecture — services, dataAnalyse a finished A/B test and write the readout — the resuAudit whether AI agents can actually use your product — docsCheck live air quality anywhere with zero API keys — Open-MeDecode a 401k or workplace retirement plan — the real cost oEnforce the simplest meeting rule that works — no agenda, noEvaluate performance fairly when output is AI-assisted — whaPlan tests for an API endpoint or service — functional, negaRe-pitch one piece of content for four audiences — the boardRedesign seat-based pricing for the agent era — when one humRun a decision asynchronously — the memo, the silent-read wiWrite an AI usage policy people can actually follow — approv