← Back to search

@thingd/cli

GitHub Actions Scanned 10d ago

CLI, Interactive TUI Dashboard, and MCP server for thingd — a fast object-first data engine for applications and AI agents.

npm
C
67.3 / 100

Versions

@thingd/cli
0.71.0latest
Jul 31, 2026
0.70.0
Jul 29, 2026
0.69.1
Jul 28, 2026
0.69.0
Jul 28, 2026
0.68.6
Jul 26, 2026
+ show 122 moreshow less
0.68.5
Jul 24, 2026
0.68.4
Jul 24, 2026
0.68.3
Jul 24, 2026
0.68.2
Jul 24, 2026
0.68.1
Jul 24, 2026
0.68.0
Jul 24, 2026
0.67.3
Jul 24, 2026
0.67.2
Jul 24, 2026
0.67.1
Jul 24, 2026
0.67.0
Jul 24, 2026
0.66.0
Jul 22, 2026
0.65.10
Jul 19, 2026
0.65.9
Jul 19, 2026
0.65.8
Jul 19, 2026
0.65.7
Jul 19, 2026
0.65.6
Jul 19, 2026
0.65.5
Jul 19, 2026
0.65.4
Jul 19, 2026
0.65.3
Jul 18, 2026
0.65.2
Jul 18, 2026
0.65.1
Jul 18, 2026
0.65.0
Jul 18, 2026
0.64.1
Jul 18, 2026
0.64.0
Jul 18, 2026
0.63.0
Jul 18, 2026
0.62.0
Jul 17, 2026
0.61.0
Jul 15, 2026
0.60.0
Jul 15, 2026
0.59.0
Jul 15, 2026
0.58.2
Jul 15, 2026
0.58.1
Jul 15, 2026
0.58.0
Jul 15, 2026
0.57.0
Jul 15, 2026
0.56.0
Jul 15, 2026
0.55.0
Jul 15, 2026
0.54.0
Jul 15, 2026
0.53.2
Jul 15, 2026
0.53.1
Jul 15, 2026
0.53.0
Jul 15, 2026
0.52.10
Jul 15, 2026
0.52.9
Jul 15, 2026
0.52.8
Jul 15, 2026
0.52.7
Jul 15, 2026
0.52.6
Jul 15, 2026
0.52.5
Jul 15, 2026
0.52.4
Jul 15, 2026
0.52.3
Jul 15, 2026
0.52.2
Jul 15, 2026
0.52.1
Jul 14, 2026
0.52.0
Jul 14, 2026
0.51.4
Jul 14, 2026
0.51.3
Jul 14, 2026
0.51.2
Jul 14, 2026
0.51.1
Jul 14, 2026
0.51.0
Jul 14, 2026
0.50.5
Jul 14, 2026
0.50.4
Jul 14, 2026
0.50.3
Jul 14, 2026
0.50.2
Jul 14, 2026
0.50.1
Jul 14, 2026
0.50.0
Jul 14, 2026
0.49.9
Jul 13, 2026
0.49.8
Jul 13, 2026
0.49.7
Jul 13, 2026
0.49.6
Jul 13, 2026
0.49.5
Jul 13, 2026
0.49.4
Jul 13, 2026
0.49.3
Jul 12, 2026
0.49.2
Jul 12, 2026
0.49.1
Jul 10, 2026
0.49.0
Jul 9, 2026
0.48.1
Jul 8, 2026
0.48.0
Jul 5, 2026
0.47.5
Jul 4, 2026
0.47.4
Jul 3, 2026
0.47.3
Jul 3, 2026
0.47.2
Jul 3, 2026
0.47.1
Jul 3, 2026
0.47.0
Jul 3, 2026
0.46.0
Jul 2, 2026
0.45.1
Jul 1, 2026
0.45.0
Jun 30, 2026
0.44.3
Jun 30, 2026
0.44.2
Jun 30, 2026
0.44.1
Jun 30, 2026
0.44.0
Jun 30, 2026
0.43.0
Jun 30, 2026
0.42.1
Jun 30, 2026
0.42.0
Jun 30, 2026
0.41.3
Jun 30, 2026
0.41.2
Jun 30, 2026
0.41.1
Jun 30, 2026
0.41.0
Jun 29, 2026
0.40.3
Jun 29, 2026
0.40.2
Jun 29, 2026
0.40.1
Jun 29, 2026
0.40.0
Jun 29, 2026
0.39.0
Jun 28, 2026
0.38.2
Jun 28, 2026
0.38.1
Jun 28, 2026
0.38.0
Jun 28, 2026
0.37.11
Jun 25, 2026
0.37.10
Jun 25, 2026
0.37.9
Jun 25, 2026
0.37.8
Jun 25, 2026
0.37.7
Jun 25, 2026
0.37.6
Jun 24, 2026
0.37.5
Jun 24, 2026
0.37.4
Jun 24, 2026
0.37.3
Jun 24, 2026
0.37.2
Jun 24, 2026
0.37.1
Jun 24, 2026
0.37.0
Jun 24, 2026
0.36.0
Jun 23, 2026
0.35.0
Jun 23, 2026
0.34.0
Jun 23, 2026
0.33.2
Jun 22, 2026
0.33.1
Jun 22, 2026
0.33.0
Jun 22, 2026
0.32.2
Jun 22, 2026
0.32.0
Jun 22, 2026
0.31.0
Jun 21, 2026
unattributed
0.17.1latest
first seen Jun 6, 2026
PermissionsTool SafetyAuthAnnotationsCode QualityStabilitySpecVuln HistoryAuthorTransparencyCommunity

Tools 49

thing_search
annotations: verified low

Search thingd objects and events by full-text query. Returns matching items ranked by relevance using Tantivy BM25 with stemming. Use this to find previously stored memories, notes, or events by keyword or phrase. Accepts a query string and optional filter by collection names, metadata key-value pairs, and a result limit. Returns an array of matching objects with relevance scores.

limit number query string filter record collections array
readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
thing_get
annotations: verified low

Read one thingd object by collection name and id. Returns the full object if found, or null if not found. Use this to retrieve a specific stored record when you know its exact collection and id. Returns a single object or null.

id string collection string
readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
thing_put
annotations: verified low

Create or replace one object-shaped memory record in a collection. The object must have an 'id' field. If an object with the same id already exists in the collection, it is replaced. Use this to store memories, notes, tasks, or any structured data. Returns the stored object with collection, version, and timestamps.

collection string expectedVersion number
readOnlyHint false openWorldHint false idempotentHint false destructiveHint false
thing_delete
annotations: verified low

Delete one thingd object by collection name and id. Permanently removes the object from the store. Returns a result indicating whether the deletion was successful. Use this to remove outdated or incorrect records.

id string collection string
readOnlyHint false openWorldHint false idempotentHint true destructiveHint true
thing_events_append
annotations: verified low

Append an event to a named event stream. Events are append-only, ordered records with a 'type' field and arbitrary payload. Use this to record occurrences, state changes, or audit entries. Each event gets an auto-incremented sequence id. Returns the stored event with id, stream, and timestamp.

stream string
readOnlyHint false openWorldHint false idempotentHint false destructiveHint false
thing_events_list
annotations: verified low

List events from a thingd stream, optionally filtered by stream name, starting from a specific sequence number, with a configurable limit, or filtered by timestamp. Use this to review recent activity, replay events, or audit changes. Returns an array of events ordered by sequence.

limit number since string stream string fromSequence number
readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
thing_queue_push
annotations: verified low

Push a durable job onto a named queue. Jobs have a JSON payload and can include an idempotency key, max retry attempts, and a delay before the job becomes ready. Use this to schedule background work like processing, notifications, or data pipelines. Returns the created job with id, queue, and status.

queue string delayMs number priority number maxAttempts number idempotencyKey string
readOnlyHint false openWorldHint false idempotentHint false destructiveHint false
thing_queue_claim
annotations: verified low

Claim the next ready job from a queue. The job is leased for a configurable duration (default 30s). If not acked or nacked before the lease expires, it returns to the ready state. Returns the claimed job with payload, or null if no jobs are ready. Use this to process queue work in a worker loop.

queue string leaseMs number
readOnlyHint false openWorldHint false idempotentHint false destructiveHint false
thing_queue_ack
annotations: verified low

Mark one leased queue job as completed. This removes the job from the queue permanently. Call this after successfully processing a claimed job. Returns a result with ok status and the final job status.

id string queue string
readOnlyHint false openWorldHint false idempotentHint false destructiveHint false
thing_queue_nack
annotations: verified low

Reject a leased queue job for retry or dead-letter routing. If the job has remaining attempts, it goes back to ready (optionally after a delay). If attempts are exhausted, it moves to the dead-letter list. Optionally attach an error message. Returns a result with ok status and the updated job status.

id string error string queue string delayMs number
readOnlyHint false openWorldHint false idempotentHint false destructiveHint false
thing_queue_list
annotations: verified low

List all jobs in a queue across all states (ready, leased, dead-letter). Use this to inspect queue contents, monitor backlog, or debug stuck jobs. Returns an array of job objects with id, payload, status, attempts, and timestamps.

queue string
readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
thing_queue_dead
annotations: verified low

List dead-letter jobs in a queue. These are jobs that exhausted all retry attempts. Use this to inspect failed work, diagnose errors, or decide whether to retry or discard. Returns an array of dead-letter job objects.

queue string
readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
thing_objects_list
annotations: verified low

List objects in a collection with optional filtering, sorting, limit, and offset. Returns an array of objects. Use sortBy.field to sort by id, collection, created_at, updated_at, or version.

field enum limit number filter record offset number direction enum collection string
readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
thing_count_objects
annotations: verified low

Count all objects stored across all collections. Returns a single number representing the total object count. Use this for quick inventory checks or monitoring storage usage.

readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
thing_count_objects_in_collection
annotations: verified low

Count objects in a specific collection. Returns a single number. Uses an indexed query for O(log n) performance.

collection string
readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
thing_count_events
annotations: verified low

Count all events across all streams. Returns a single number representing the total event count. Use this to monitor event volume or check stream activity.

readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
thing_count_active_jobs
annotations: verified low

Count all active (non-dead) queue jobs across all queues. Includes ready, leased, and delayed jobs. Use this to monitor queue depth and worker load.

readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
thing_count_dead_jobs
annotations: verified low

Count all dead-letter queue jobs across all queues. These are jobs that failed all retry attempts. Use this to monitor failure rates and decide when to investigate or discard.

readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
thing_list_collections
annotations: verified low

List all object collection names in the store. Returns an array of collection name strings. Use this to discover what data is stored before searching or querying.

readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
thing_list_streams
annotations: verified low

List all event stream names in the store. Returns an array of stream name strings. Use this to discover available event streams before listing or appending events.

readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
thing_list_queues
annotations: verified low

List all queue names in the store. Returns an array of queue name strings. Use this to discover available queues before pushing or claiming jobs.

readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
thing_create_index
annotations: verified low

Create a functional index on a JSON body field for a collection. Subsequent listObjects calls with filter on this field will use the index for O(log n) lookups instead of full table scans. Idempotent — recreating an existing index is a no-op.

field string unique boolean collection string
readOnlyHint false openWorldHint false idempotentHint true destructiveHint false
thing_delete_index
annotations: verified low

Delete a custom functional index.

field string collection string
readOnlyHint false openWorldHint false idempotentHint true destructiveHint true
thing_list_indexes
annotations: verified low

List all custom functional indexes. Returns an array of [collection, field] pairs.

readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
thing_objects_put_batch
annotations: verified low

Create or replace multiple objects in a collection in a single operation. More efficient than calling thing_put repeatedly. Returns the array of stored objects.

id string collection string
readOnlyHint false openWorldHint false idempotentHint false destructiveHint false
thing_objects_delete_batch
annotations: verified low

Delete multiple objects by ID in a single operation. Returns the count of deleted objects.

ids array collection string
readOnlyHint false openWorldHint false idempotentHint true destructiveHint true
thing_objects_get_batch
annotations: verified low

Read multiple objects by ID in a single operation. Returns an array of objects (null for missing IDs). More efficient than calling thing_get repeatedly.

ids array collection string
readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
thing_link_create
annotations: verified low

Create a directed graph link between two references (e.g., thingd objects, external URLs). You can optionally assign a linkType (e.g., 'parent', 'related_to'), weight, and metadata JSON string.

toRef string weight number fromRef string linkType string metadataJson string
readOnlyHint false openWorldHint false idempotentHint false destructiveHint false
thing_link_delete
annotations: verified low

Delete a graph link by its id. Returns an object with a deleted boolean.

id string
readOnlyHint false openWorldHint false idempotentHint true destructiveHint true
thing_link_get
annotations: verified low

Get a graph link by its id.

id string
readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
thing_link_neighbors
annotations: verified low

Get all links connected to a specific reference. You can filter by direction (Outgoing, Incoming, Both) and linkType.

limit number linkType string direction enum reference string
readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
thing_link_count
annotations: verified low

Count all graph links in the store.

readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
thing_aggregate
annotations: verified low

Run aggregate queries on objects in a collection. Supports count, sum, avg, min, max with optional groupBy and filter.

field string filter record groupBy string function enum collection string
readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
thing_timeseries
annotations: verified low

Run time-series aggregation on objects. Buckets objects by hour/day/week/month and applies an aggregate function.

to string from string field string bucket enum filter record function enum collection string
readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
thing_vector_search
annotations: verified low

Search objects by vector similarity (cosine similarity). Provide a query vector as an array of floats (e.g. [0.1, 0.2, 0.3]) and optionally set topK and a metadata filter. Returns matching objects ranked by similarity score.

topK number filter record vector array collection string
readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
thing_schema
annotations: verified low

Reflect the schema of one or all collections by sampling stored objects. Returns inferred field names, types, and sample values.

collection string
readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
thing_schema_validate
annotations: verified low

Parse and validate schema.thingd source without changing stored data. Returns canonical schema JSON and a stable SHA-256 hash.

source string
readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
thing_migrations
annotations: verified low

List durable schema migration records and their applied hashes.

readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
thing_nlq
annotations: verified low

Ask a natural language question about your data. Requires NLQ configuration with an LLM endpoint.

question string collection string
readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
thing_scheduler_schedule
annotations: verified low

Create or update a recurring schedule with a cron expression. Schedules persist across restarts and emit lifecycle events (started, completed, failed, disabled). The handler executes when the cron triggers. Returns the created schedule with nextRunAt.

id string enabled boolean payload record timezone string expression string maxConsecutiveFails number
readOnlyHint false openWorldHint false idempotentHint true destructiveHint false
thing_scheduler_schedule_interval
annotations: verified low

Create a schedule that runs at a fixed interval (e.g. every 5 minutes). Accepts intervalMs for the delay between runs. Returns the created schedule.

id string enabled boolean payload record intervalMs number maxConsecutiveFails number
readOnlyHint false openWorldHint false idempotentHint true destructiveHint false
thing_scheduler_schedule_once
annotations: verified low

Create a schedule that runs once at a specific ISO timestamp. The schedule auto-disables after execution. Returns the created schedule.

id string runAt string payload record
readOnlyHint false openWorldHint false idempotentHint true destructiveHint false
thing_scheduler_list
annotations: verified low

List all registered schedules with their current status, next run time, and run/fail counts. Returns an array of schedule objects.

readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
thing_scheduler_get
annotations: verified low

Get details of a single schedule by ID including its expression, next run, last status, and run/fail counts. Returns null if not found.

id string
readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
thing_scheduler_stats
annotations: verified low

Get aggregate statistics for the scheduler: total schedules, enabled, disabled, currently running, and the next scheduled run.

readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
thing_scheduler_pause
annotations: verified low

Pause a schedule so it stops triggering. The schedule remains stored and can be resumed later. Returns the updated schedule.

id string
readOnlyHint false openWorldHint false idempotentHint false destructiveHint false
thing_scheduler_resume
annotations: verified low

Resume a paused schedule. The next run time is recalculated from the current time. Returns the updated schedule.

id string
readOnlyHint false openWorldHint false idempotentHint false destructiveHint false
thing_scheduler_run
annotations: verified low

Immediately execute a schedule's handler, regardless of its next run time. Useful for testing or manual triggers. The schedule must have a registered handler.

id string
readOnlyHint false openWorldHint false idempotentHint false destructiveHint false
thing_scheduler_remove
annotations: verified low

Permanently delete a schedule and its handler. This cannot be undone. Returns whether the schedule was deleted.

id string
readOnlyHint false openWorldHint false idempotentHint false destructiveHint true

Permissions 4

network medium
Server uses network capabilities via: fetch(), http
filesystem low
Server uses filesystem capabilities via: fs, fs sync ops, fs.promises, path
shell high
Server uses shell capabilities via: child_process, execSync(), spawn()
env_vars low
Server uses env_vars capabilities via: process.env

Scan Findings 155

info
Tool 'thing_get' annotations are consistent annotation_checker · 80%
info
Tool 'thing_put' annotations are consistent annotation_checker · 80%
info
Tool 'thing_delete' annotations are consistent annotation_checker · 80%
info
Tool 'thing_events_append' annotations are consistent annotation_checker · 80%
info
Tool 'thing_events_list' annotations are consistent annotation_checker · 80%
info
Tool 'thing_queue_push' annotations are consistent annotation_checker · 80%
info
Tool 'thing_queue_claim' annotations are consistent annotation_checker · 80%
info
Tool 'thing_queue_ack' annotations are consistent annotation_checker · 80%
info
Tool 'thing_queue_nack' annotations are consistent annotation_checker · 80%
info
Tool 'thing_queue_list' annotations are consistent annotation_checker · 80%
info
Tool 'thing_queue_dead' annotations are consistent annotation_checker · 80%
info
Tool 'thing_objects_list' annotations are consistent annotation_checker · 80%
info
Tool 'thing_count_objects' annotations are consistent annotation_checker · 80%
info
Tool 'thing_count_objects_in_collection' annotations are consistent annotation_checker · 80%
info
Tool 'thing_count_events' annotations are consistent annotation_checker · 80%
info
Tool 'thing_count_active_jobs' annotations are consistent annotation_checker · 80%
info
Tool 'thing_count_dead_jobs' annotations are consistent annotation_checker · 80%
info
Tool 'thing_list_collections' annotations are consistent annotation_checker · 80%
info
Tool 'thing_list_streams' annotations are consistent annotation_checker · 80%
info
Tool 'thing_list_queues' annotations are consistent annotation_checker · 80%
info
Tool 'thing_create_index' annotations are consistent annotation_checker · 80%
info
Tool 'thing_delete_index' annotations are consistent annotation_checker · 80%
info
Tool 'thing_list_indexes' annotations are consistent annotation_checker · 80%
info
Tool 'thing_objects_put_batch' annotations are consistent annotation_checker · 80%
info
Tool 'thing_objects_delete_batch' annotations are consistent annotation_checker · 80%
info
Tool 'thing_objects_get_batch' annotations are consistent annotation_checker · 80%
info
Tool 'thing_link_create' annotations are consistent annotation_checker · 80%
info
Tool 'thing_link_delete' annotations are consistent annotation_checker · 80%
info
Tool 'thing_link_get' annotations are consistent annotation_checker · 80%
info
Tool 'thing_link_neighbors' annotations are consistent annotation_checker · 80%
info
Tool 'thing_link_count' annotations are consistent annotation_checker · 80%
info
Tool 'thing_aggregate' annotations are consistent annotation_checker · 80%
info
Tool 'thing_timeseries' annotations are consistent annotation_checker · 80%
info
Tool 'thing_vector_search' annotations are consistent annotation_checker · 80%
info
Tool 'thing_schema' annotations are consistent annotation_checker · 80%
info
Tool 'thing_schema_validate' annotations are consistent annotation_checker · 80%
info
Tool 'thing_migrations' annotations are consistent annotation_checker · 80%
info
Tool 'thing_nlq' annotations are consistent annotation_checker · 80%
info
Tool 'thing_scheduler_schedule' annotations are consistent annotation_checker · 80%
info
Tool 'thing_scheduler_schedule_interval' annotations are consistent annotation_checker · 80%
info
Tool 'thing_scheduler_schedule_once' annotations are consistent annotation_checker · 80%
info
Tool 'thing_scheduler_list' annotations are consistent annotation_checker · 80%
info
Tool 'thing_scheduler_get' annotations are consistent annotation_checker · 80%
info
Tool 'thing_scheduler_stats' annotations are consistent annotation_checker · 80%
info
Tool 'thing_scheduler_pause' annotations are consistent annotation_checker · 80%
info
Tool 'thing_scheduler_resume' annotations are consistent annotation_checker · 80%
info
Tool 'thing_scheduler_run' annotations are consistent annotation_checker · 80%
info
Tool 'thing_scheduler_remove' annotations are consistent annotation_checker · 80%
medium
OAuth implementation without PKCE auth_checker · 75%
info
Sandbox failed to start for behavioral verification behavioral_verifier · 100%
info
Tool 'thing_search' annotations are consistent annotation_checker · 80%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-26pp-8wgv-hjvm) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-2gcr-mfcq-wcc3) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-3hrh-pfw6-9m5x) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-3vhc-576x-3qv4) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-458j-xx4x-4375) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-5pq2-9x2x-5p6w) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-69xw-7hcm-h432) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-6wqw-2p9w-4vw4) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-79qm-7rj5-m7r9) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-88fw-hqm2-52qc) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-8j4g-w8fx-2239) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-92vj-g62v-jqhh) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-9r54-q6cx-xmh5) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-9vqf-7f2p-gf9v) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-f23p-vx2j-j53r) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-f577-qrjj-4474) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-f67f-6cw9-8mq4) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-gq3j-xvxp-8hrf) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-hm8q-7f3q-5f36) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-j6c9-x7qj-28xf) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-m732-5p4w-x69g) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-p6xx-57qc-3wxr) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-p77w-8qqv-26rm) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-q5qw-h33p-qvwr) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-q7jf-gf43-6x6p) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-qp7p-654g-cw7p) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-r354-f388-2fhh) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-r5rp-j6wh-rvv4) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-rv63-4mwf-qqc2) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-v8w9-8mx6-g223) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-w332-q679-j88p) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-w62v-xxxg-mg59) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-wgpf-jwqj-8h8p) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-wmmm-f939-6g9c) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-wwfh-h76j-fc44) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-xf4j-xp2r-rqqx) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-xgm2-5f3f-mvvc) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-xpcf-pg52-r92g) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-xrhx-7g5j-rcj5) dependency_analyzer · 95%
info
package.json metadata manifest_parser · 100%
info
Tool: thing_search manifest_parser · 85%
info
Tool: thing_get manifest_parser · 85%
info
Tool: thing_put manifest_parser · 85%
info
Tool: thing_delete manifest_parser · 85%
info
Tool: thing_events_append manifest_parser · 85%
info
Tool: thing_events_list manifest_parser · 85%
info
Tool: thing_queue_push manifest_parser · 85%
info
Tool: thing_queue_claim manifest_parser · 85%
info
Tool: thing_queue_ack manifest_parser · 85%
info
Tool: thing_list_queues manifest_parser · 85%
info
Tool: thing_queue_nack manifest_parser · 85%
info
Tool: thing_queue_list manifest_parser · 85%
info
Tool: thing_queue_dead manifest_parser · 85%
info
Tool: thing_objects_list manifest_parser · 85%
info
Tool: thing_count_objects manifest_parser · 85%
info
Tool: thing_count_objects_in_collection manifest_parser · 85%
info
Tool: thing_count_events manifest_parser · 85%
info
Tool: thing_count_active_jobs manifest_parser · 85%
info
Tool: thing_count_dead_jobs manifest_parser · 85%
info
Tool: thing_list_collections manifest_parser · 85%
info
Tool: thing_list_streams manifest_parser · 85%
info
Tool: thing_create_index manifest_parser · 85%
info
Tool: thing_delete_index manifest_parser · 85%
info
Tool: thing_list_indexes manifest_parser · 85%
info
Tool: thing_objects_put_batch manifest_parser · 85%
info
Tool: thing_objects_delete_batch manifest_parser · 85%
info
Tool: thing_objects_get_batch manifest_parser · 85%
info
Tool: thing_link_create manifest_parser · 85%
info
Tool: thing_link_delete manifest_parser · 85%
info
Tool: thing_link_get manifest_parser · 85%
info
Tool: thing_link_neighbors manifest_parser · 85%
info
Tool: thing_link_count manifest_parser · 85%
info
Tool: thing_aggregate manifest_parser · 85%
info
Tool: thing_timeseries manifest_parser · 85%
info
Tool: thing_vector_search manifest_parser · 85%
info
Tool: thing_schema manifest_parser · 85%
info
Tool: thing_schema_validate manifest_parser · 85%
info
Tool: thing_migrations manifest_parser · 85%
info
Tool: thing_nlq manifest_parser · 85%
info
Tool: thing_scheduler_schedule manifest_parser · 85%
info
Tool: thing_scheduler_schedule_interval manifest_parser · 85%
info
Tool: thing_scheduler_schedule_once manifest_parser · 85%
info
Tool: thing_scheduler_list manifest_parser · 85%
info
Tool: thing_scheduler_get manifest_parser · 85%
info
Tool: thing_scheduler_stats manifest_parser · 85%
info
Tool: thing_scheduler_pause manifest_parser · 85%
info
Tool: thing_scheduler_resume manifest_parser · 85%
info
Tool: thing_scheduler_run manifest_parser · 85%
info
Tool: thing_scheduler_remove manifest_parser · 85%
info
Transport: streamable-http manifest_parser · 80%
info
Required env vars (14) manifest_parser · 80%
info
Sandbox failed to start for output poisoning scan output_poisoning · 100%
medium
Permission: network access detected permission_analyzer · 80%
low
Permission: filesystem access detected permission_analyzer · 90%
high
Permission: shell access detected permission_analyzer · 95%
low
Permission: env_vars access detected permission_analyzer · 90%
critical
Tool poisoning in 'thing_queue_ack': Cross-tool sequencing directive poisoning · 85%
info
SBOM generated: 27 components sbom_generator · 100%
high
Hardcoded Password found in sayanmohsin-thingd-b22594d/docs/app-backend.md secret_scanner · 65%
high
Authorization Bearer Token found in sayanmohsin-thingd-b22594d/examples/sales-db/mcp-direct-list.mjs secret_scanner · 70%
high
Hardcoded Password found in sayanmohsin-thingd-b22594d/examples/react-native-expo/App.tsx secret_scanner · 65%
high
Hardcoded Password found in sayanmohsin-thingd-b22594d/crates/thingd/src/connector.rs secret_scanner · 65%
high
Authorization Bearer Token found in sayanmohsin-thingd-b22594d/crates/thingd-server/src/rest.rs secret_scanner · 70%
medium
No build provenance detected (SLSA L0) slsa_assessor · 90%