@grackle-ai/mcp
MCP (Model Context Protocol) server for Grackle — translates MCP tool calls to ConnectRPC
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| typosquat | typosquat.levenshtein:yup | AI (typosquat): Scoped package @grackle-ai/mcp is not a typosquat of yup; Levenshtein match is coincidental. | ai | |
| phantom-deps | phantom-dep:@bufbuild/protobuf | AI (phantom-deps): @bufbuild/protobuf is a legitimate declared dep used via generated protobuf code; phantom-dep heuristic fires on indirect usage patterns. | ai |
Versions (showing 11 of 211)
| Version | Deps | Published |
|---|---|---|
| 0.72.1 | 7 / 4 | |
| 0.72.0 | 7 / 4 | |
| 0.71.3 | 7 / 4 | |
| 0.71.2 | 7 / 4 | |
| 0.71.1 | 7 / 4 | |
| 0.71.0 | 7 / 4 | |
| 0.70.6 | 7 / 4 | |
| 0.70.5 | 7 / 4 | |
| 0.70.4 | 7 / 4 | |
| 0.70.3 | 7 / 4 | |
| 0.70.2 | 7 / 4 |
v0.72.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.72.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.71.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.71.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.71.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.71.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.70.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.70.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.70.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.70.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.70.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.