This repository may not be an MCP server
We could not detect MCP SDK imports or tool registrations.
HTML comments in tool descriptions may contain hidden instructions intended to influence LLM reasoning.
const marker = '<!-- welcome-comment -->';
Remove HTML comments from description strings. Use source code comments instead.
Backslash-based directory traversal patterns targeting Windows file systems.
Please update your PR to use a \`https://github.com/...\` repository link.`
Normalize path separators and apply traversal checks for both forward and backslashes.
Using GitHub Actions with branch references instead of SHA pins enables supply chain attacks.
uses: actions/github-script@v7
Pin GitHub Actions to full commit SHAs: uses: actions/checkout@abc123...
HTML comments in tool descriptions may contain hidden instructions intended to influence LLM reasoning.
const marker = '<!-- glama-check -->';
Remove HTML comments from description strings. Use source code comments instead.
HTML comments in tool descriptions may contain hidden instructions intended to influence LLM reasoning.
const marker = '<!-- glama-badge-check -->';
Remove HTML comments from description strings. Use source code comments instead.
HTML comments in tool descriptions may contain hidden instructions intended to influence LLM reasoning.
const marker = '<!-- emoji-check -->';
Remove HTML comments from description strings. Use source code comments instead.
HTML comments in tool descriptions may contain hidden instructions intended to influence LLM reasoning.
const marker = '<!-- duplicate-check -->';
Remove HTML comments from description strings. Use source code comments instead.
HTML comments in tool descriptions may contain hidden instructions intended to influence LLM reasoning.
const marker = '<!-- url-check -->';
Remove HTML comments from description strings. Use source code comments instead.
HTML comments in tool descriptions may contain hidden instructions intended to influence LLM reasoning.
const marker = '<!-- name-check -->';
Remove HTML comments from description strings. Use source code comments instead.
Using GitHub Actions with branch references instead of SHA pins enables supply chain attacks.
uses: actions/checkout@v4
Pin GitHub Actions to full commit SHAs: uses: actions/checkout@abc123...
Using GitHub Actions with branch references instead of SHA pins enables supply chain attacks.
uses: actions/github-script@v7
Pin GitHub Actions to full commit SHAs: uses: actions/checkout@abc123...