Behavioral coverage
Reading a tool’s definition is cheap, so everyone reports big scan numbers. Running the server costs a sandbox each, and most of them refuse to start. This is how many we have actually executed — and exactly where our coverage stops.
Where our coverage stops
We attempted 115 more servers that never started, so we have nothing to report about them. We would rather publish that than quietly count them as scanned.
The auditor runs on its own
A one-time scan goes stale the moment a package publishes a new version. Ours wakes on a schedule, re-audits packages whose artifact changed, and records every run.
How to read these numbers. Counts only tools we actually executed in an isolated sandbox. Catalog entries carrying a heuristic score are NOT counted as audited here. Our catalog lists 766 tools, and most of them have never been run by us — a heuristic score is not an audit, and this page does not count one as if it were.
Generated Thu, 10 Sep 2026 20:55:21 GMT · recomputed every 5 minutes