← Back to search Server uses network capabilities via: fetch() Server uses filesystem capabilities via: fs/promises Server uses shell capabilities via: child_process, execSync(), spawn(), spawnSync() Server uses env_vars capabilities via: process.env
@tuttiai/mcp
MCP bridge voice for Tutti — wrap any MCP server as a Tutti voice
D
40 / 100
Versions
0.1.2latestMay 10, 2026
0.1.1Apr 16, 2026
0.1.0Apr 12, 2026
Tools 8
test-voice annotations: none low
echo annotations: none low
Echo input text.
send annotations: none low
Send a token.
leaky annotations: none low
Throws with a leaked key.
send_email annotations: none low
send
read_file annotations: none low
read
noop annotations: none low
Always returns ok.
remember_fact annotations: none low
Remember a fact about the user
Permissions 4
network medium filesystem low shell high env_vars low Scan Findings 65
low
Tool 'test-voice' has no annotations
low
Tool 'echo' has no annotations
low
Tool 'send' has no annotations
low
Tool 'leaky' has no annotations
low
Tool 'send_email' has no annotations
low
Tool 'read_file' has no annotations
low
Tool 'noop' has no annotations
low
Tool 'remember_fact' has no annotations
medium
OAuth implementation without PKCE
info
Sandbox failed to start for behavioral verification
medium
Excessive dependency count: 101 direct dependencies
medium
Suspicious package name: react-dom
medium
Vulnerable dependency: turbo@2.9.5 (GHSA-3qcw-2rhx-2726)
medium
Vulnerable dependency: turbo@2.9.5 (GHSA-hcf7-66rw-9f5r)
medium
Vulnerable dependency: vitest@3.2.4 (GHSA-5xrq-8626-4rwp)
medium
Vulnerable dependency: astro@6.1.6 (GHSA-2pvr-wf23-7pc7)
medium
Vulnerable dependency: astro@6.1.6 (GHSA-4g3v-8h47-v7g6)
medium
Vulnerable dependency: astro@6.1.6 (GHSA-7pw4-f3q4-r2p2)
medium
Vulnerable dependency: astro@6.1.6 (GHSA-8hv8-536x-4wqp)
medium
Vulnerable dependency: astro@6.1.6 (GHSA-f48w-9m4c-m7f5)
medium
Vulnerable dependency: astro@6.1.6 (GHSA-jrpj-wcv7-9fh9)
medium
Vulnerable dependency: astro@6.1.6 (GHSA-xr5h-phrj-8vxv)
medium
Vulnerable dependency: sharp@0.33.0 (GHSA-f88m-g3jw-g9cj)
medium
Vulnerable dependency: vite@6.0.0 (GHSA-356w-63v5-8wf4)
medium
Vulnerable dependency: vite@6.0.0 (GHSA-4r4m-qw57-chr8)
medium
Vulnerable dependency: vite@6.0.0 (GHSA-4w7w-66w2-5vf9)
medium
Vulnerable dependency: vite@6.0.0 (GHSA-859w-5945-r5v3)
medium
Vulnerable dependency: vite@6.0.0 (GHSA-93m4-6634-74q7)
medium
Vulnerable dependency: vite@6.0.0 (GHSA-fx2h-pf6j-xcff)
medium
Vulnerable dependency: vite@6.0.0 (GHSA-g4jq-h2w9-997c)
medium
Vulnerable dependency: vite@6.0.0 (GHSA-jqfw-vq24-v9c3)
medium
Vulnerable dependency: vite@6.0.0 (GHSA-p9ff-h696-f583)
medium
Vulnerable dependency: vite@6.0.0 (GHSA-v6wh-96g9-6wx3)
medium
Vulnerable dependency: vite@6.0.0 (GHSA-vg6x-rcgg-rjx6)
medium
Vulnerable dependency: vite@6.0.0 (GHSA-x574-m823-4x7w)
medium
Vulnerable dependency: vite@6.0.0 (GHSA-xcj6-pq6g-qj4x)
medium
Vulnerable dependency: ws@8.17.0 (GHSA-3h5v-q93c-6h6q)
medium
Vulnerable dependency: ws@8.17.0 (GHSA-58qx-3vcg-4xpx)
medium
Vulnerable dependency: ws@8.17.0 (GHSA-96hv-2xvq-fx4p)
medium
Vulnerable dependency: @opentelemetry/core@2.6.1 (GHSA-8988-4f7v-96qf)
medium
Vulnerable dependency: nodemailer@8.0.7 (GHSA-268h-hp4c-crq3)
medium
Vulnerable dependency: nodemailer@8.0.7 (GHSA-p6gq-j5cr-w38f)
medium
Vulnerable dependency: nodemailer@8.0.7 (GHSA-r7g4-qg5f-qqm2)
medium
Vulnerable dependency: nodemailer@8.0.7 (GHSA-wqvq-jvpq-h66f)
medium
Buffer.from base64 in tuttiai-tutti-c1f199e/packages/server/src/routes/realtime-bridge.ts:108
medium
Buffer.from base64 in tuttiai-tutti-c1f199e/packages/cli/src/commands/publish.ts:232
medium
Buffer.from base64 in tuttiai-tutti-c1f199e/voices/github/src/tools/get-file-contents.ts:39
info
package.json metadata
info
Tool: test-voice
info
Tool: echo
info
Tool: send
info
Tool: leaky
info
Tool: send_email
info
Tool: read_file
info
Tool: noop
info
Tool: remember_fact
info
Required env vars (41)
info
Sandbox failed to start for output poisoning scan
medium
Permission: network access detected
low
Permission: filesystem access detected
high
Permission: shell access detected
low
Permission: env_vars access detected
info
SBOM generated: 1468 components
critical
Database URL with Password found in tuttiai-tutti-c1f199e/docker-compose.yml
medium
No build provenance detected (SLSA L0)