No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by nikolai-vysotskyi · MCP Server · ★ 179
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is trace-mcp safe to install? View the security audit →
trace-mcp <img src="https://api.securityscorecards.dev/projects/github.com/nikolai-vysotskyi/trace-mcp/badge" alt="OpenSSF Scorec
| Stars | 179 |
| Forks | 21 |
| Language | TypeScript |
| Category | MCP Server |
| License | MIT |
| Quality Score | 62.7864556404549/100 |
| Open Issues | 17 |
| Last Updated | 2026-09-23 |
| Created | 2026-04-03 |
| Platforms | claude-code, codex, mcp, node |
| Est. Tokens | ~23k |
These tools work well together with trace-mcp for enhanced workflows:
Looking for a trace-mcp alternative? If you're comparing trace-mcp with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
Structural code intelligence for AI agents — semantic search, knowledge graphs, and a built-in MCP server in o
One command gives AI agents instant codebase context. ~250 tokens replaces 50,000+ tokens of exploration. Auto
🏛 [UNDER CONSTRUCTION] A (roman) claude plugin marketplace
Local codebase intelligence CLI + MCP server for AI coding agents: SQLite code graph, 28 languages, 287 comman
Daymon puts your favorite AI to work 24/7. It schedules, remembers, and orchestrates your own virtual team. Fr
DeepContext is an MCP server that adds symbol-aware semantic search to Claude Code, Codex CLI, and other agent
Explore other popular mcp server tools:
trace-mcp is Framework-aware code intelligence MCP server — 88 framework integrations, 81 languages, 72.7% fewer input tokens to review a pull request, comprehension at parity. It is categorized as a MCP Server with 179 GitHub stars.
trace-mcp is primarily written in TypeScript. It covers topics such as ai-agents, claude, claude-ai.
You can find installation instructions and usage details in the trace-mcp GitHub repository at github.com/nikolai-vysotskyi/trace-mcp. The project has 179 stars and 21 forks, indicating an active community.
trace-mcp is released under the MIT license, making it free to use and modify according to the license terms.
The top alternatives to trace-mcp on Agent Skills Hub include octocode, stacklit, claude-emporium. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: