Is the npm:@10iii/air-mcp-server MCP server safe to use?
Independent trust grade A- (91/100). Static analysis of npm package @10iii/air-mcp-server@0.2.8 (stdio server — no remote endpoint). Reliability/behavioral signals require running it; not measured. wmcp.sh continuously watches npm:@10iii/air-mcp-server for tool drift and rug-pulls. The grade is free and identical whether or not the operator pays.
What it offers — 12 tools · Developer Tools
air_read
Read file content with AIR compression.
air_bash
Compress terminal/command output.
air_edit
Apply search/replace edits with AIR edit compression.
air_test
Compress test runner output.
air_grep
Compress grep output.
air_web
Extract and compress article content from HTML.
air_ls
Compress directory listing output.
air_diff
Compress git diff output.
air_session
Compress AI chat session/conversation data.
air_api
Compress API/JSON response data.
air_search
Compress search engine results.
air_media
Compress media transcripts (SRT/VTT/text subtitles).
Spec / packaging20%100
✓ depends on an MCP SDK
✓ declares a bin entry (runnable server)
✓ 12 tool(s) detected in source
Security (OWASP MCP)30%90
no high-risk patterns in sampled source
scanned 1 source file
Maintenance / popularity20%83
last published ~5mo ago
9 published versions
Tool hygiene15%95
✓ ships TypeScript types
3 runtime deps
Transparency / provenance15%90
✓ public repository linked
✓ MIT license
169 weekly downloads
Findings
INFO Static analysis of npm package @10iii/air-mcp-server@0.2.8 (stdio server — no remote endpoint). Reliability/behavioral signals require running it; not measured.
We re-grade npm:@10iii/air-mcp-server on a schedule and alert your Slack/webhook the moment its tools change or its grade drops — rug-pull insurance for the connection.
Share this report card
A 1200×630 card with the grade + audit — drop it in a post, Slack, or your repo.
A live badge — it re-verifies itself and shows current stability. Static scorecards can't. Paste it in your README or site to show users you're independently audited.
Add the wmcp.sh trust oracle as an MCP server and call grade_mcp_server / check_mcp_drift in your agent's pre-connection gate:
https://wmcp.sh/mcp/trust
How this grade is computed. An open, independent rubric — Spec conformance (20%), Security mapped to the OWASP MCP Top 10 (30%), Reliability (20%), Tool hygiene (15%), Transparency (15%) — run by connecting to the server and inspecting its real MCP surface. The grade is free and identical whether or not the operator pays. v1 uses static + spec signals from a single connection; continuous uptime, real latency, and annotation-truthing (declared readOnly vs observed behavior) layer on via the wmcp.sh proxy.