← Back to search

mc8yp

GitHub Actions Scanned 7d ago

Cumulocity IoT MCP Server - Model Context Protocol integration for IoT device management

npm
C
73.4 / 100

Versions

2.6.2latest
Jul 26, 2026
2.6.1
Jul 24, 2026
2.6.0
Jul 23, 2026
2.5.2
Jul 3, 2026
2.5.1
Jun 24, 2026
+ show 19 moreshow less
2.5.0
Jun 23, 2026
2.4.0
Jun 11, 2026
2.3.3
Jun 9, 2026
2.3.2
Jun 9, 2026
2.3.1
Jun 9, 2026
2.3.0
Jun 9, 2026
2.2.4
Jun 2, 2026
2.2.3
May 27, 2026
2.2.2
May 19, 2026
2.2.1
May 19, 2026
2.2.0
May 13, 2026
2.1.0
May 6, 2026
2.0.1
May 6, 2026
2.0.0
Apr 25, 2026
1.0.4
Jan 24, 2026
1.0.3
Dec 17, 2025
1.0.2
Dec 17, 2025
1.0.1
Dec 16, 2025
1.0.0
Dec 16, 2025
PermissionsTool SafetyAuthAnnotationsCode QualityStabilitySpecVuln HistoryAuthorTransparencyCommunity

Tools 5

get_assets
annotations: none low

List assets with server-side hierarchy filtering.

needs_user_input
annotations: none low

Attempts an elicitation — must fail cleanly through mc8yp.

status
annotations: none low

set-active-tenant
annotations: none low

Set the Cumulocity tenant for this CLI session, or pass tenantUrl: null to clear the active tenant. The tenantUrl must match one returned by the status tool. The selection is persisted across sessions so you only need to call this once (or when switching tenants). Clearing falls back to bundled-only browsing — codemode discovery still works but live API calls are unavailable until a tenant is set again.

codemode
annotations: none low

${getSafetyPreface(env)} Run an async JavaScript function against the Cumulocity API. Discovery, documentation, and typed API calls all happen inside one function — find what you need and call it in the same run. ${getSandboxNote(env)} The expensive mistake is a hasty API call: an unparameterized request returns large payloads that flood your context. \

Permissions 4

network medium
Server uses network capabilities via: fetch()
filesystem low
Server uses filesystem capabilities via: fs sync ops
shell high
Server uses shell capabilities via: child_process
env_vars low
Server uses env_vars capabilities via: process.env

Scan Findings 31

high
Permission: shell access detected permission_analyzer · 95%
low
Tool 'get_assets' has no annotations annotation_checker · 100%
low
Tool 'needs_user_input' has no annotations annotation_checker · 100%
low
Tool 'status' has no annotations annotation_checker · 100%
low
Tool 'set-active-tenant' has no annotations annotation_checker · 100%
low
Tool 'codemode' has no annotations annotation_checker · 100%
info
Sandbox failed to start for behavioral verification behavioral_verifier · 100%
medium
Vulnerable dependency: h3@catalog: (GHSA-22cc-p3c6-wpvm) dependency_analyzer · 95%
medium
Vulnerable dependency: h3@catalog: (GHSA-4hxc-9384-m385) dependency_analyzer · 95%
medium
Vulnerable dependency: h3@catalog: (GHSA-72gr-qfp7-vwhw) dependency_analyzer · 95%
medium
Vulnerable dependency: h3@catalog: (GHSA-mp2g-9vg9-f4cg) dependency_analyzer · 95%
medium
Vulnerable dependency: h3@catalog: (GHSA-wr4h-v87w-p3r7) dependency_analyzer · 95%
medium
Vulnerable dependency: srvx@catalog: (GHSA-p36q-q72m-gchr) dependency_analyzer · 95%
medium
Vulnerable dependency: valibot@catalog: (GHSA-5qjj-4xww-7phc) dependency_analyzer · 95%
medium
Vulnerable dependency: vitest@catalog: (GHSA-5xrq-8626-4rwp) dependency_analyzer · 95%
medium
Vulnerable dependency: vitest@catalog: (GHSA-9crc-q9x8-hgqq) dependency_analyzer · 95%
info
package.json metadata manifest_parser · 100%
info
Tool: get_assets manifest_parser · 75%
info
Tool: needs_user_input manifest_parser · 75%
info
Tool: status manifest_parser · 75%
info
Tool: set-active-tenant manifest_parser · 75%
info
Tool: codemode manifest_parser · 75%
info
Transport: stdio manifest_parser · 90%
info
Required env vars (9) manifest_parser · 80%
info
Sandbox failed to start for output poisoning scan output_poisoning · 100%
medium
Permission: network access detected permission_analyzer · 70%
low
Permission: filesystem access detected permission_analyzer · 90%
low
Permission: env_vars access detected permission_analyzer · 90%
info
SBOM generated: 29 components sbom_generator · 100%
high
Hardcoded Password found in schplitt-mc8yp-3323a11/src/cli/subcommands/subcommands/add.ts secret_scanner · 65%
medium
No build provenance detected (SLSA L0) slsa_assessor · 90%