How the score works
Each rule that fires adds its points once, however many tools trigger it. The score is capped at 100: 60 or more means don't install as is, 35 to 59 install only with changes, 15 to 34 review first, and below 15 no major red flags.
| Rule | Severity | Points |
|---|---|---|
| Tool description contains hidden instructions | critical | +30 |
| Install command pipes a download straight into a shell | critical | +25 |
| Description gives instructions about other tools | high | +20 |
| Declared read-only, but the tool looks like it acts | high | +20 |
| Tool can run code or shell commands | high | +18 |
| Tool reads secrets or credentials | high | +15 |
| Install command isn't pinned to a version | medium | +12 |
| Tool can write, move or delete files | medium | +10 |
| Tool fetches arbitrary URLs | medium | +10 |
| Destructive tool | medium | +8 |
| Unusually long tool description | low | +4 |
| More than 20 tools | low | +4 |
| Tools that act carry no behaviour annotations | low | +3 |
Rules match the tool names, descriptions, input schemas and annotations you paste. Pattern checks can miss things and can flag harmless text, so read each finding's evidence.