Open Registry Poc runs on your own machine — the client starts it, so there is no endpoint to ping. 27 installs a week from npm.
PoC: Open Registry supply chain — unvetted server listing (security research)
The linked repository no longer exists on GitHub — it was deleted or made private.
Quiet is not dead — but it is worth knowing when it wakes up, or when someone else takes it over. We watch the repository and tell you either way.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add open-registry-poc -- npx -y @nottiboy1337/mcp-open-registry-poc
{
"mcpServers": {
"open-registry-poc": {
"args": [
"-y",
"@nottiboy1337/mcp-open-registry-poc"
],
"command": "npx"
}
}
}
[mcp_servers.open-registry-poc]
command = "npx"
args = ["-y", "@nottiboy1337/mcp-open-registry-poc"]
{
"mcpServers": {
"open-registry-poc": {
"args": [
"-y",
"@nottiboy1337/mcp-open-registry-poc"
],
"command": "npx"
}
}
}
{
"mcpServers": {
"open-registry-poc": {
"args": [
"-y",
"@nottiboy1337/mcp-open-registry-poc"
],
"command": "npx"
}
}
}
PoC benign MCP server for update-hijack security research
Scans MCP servers for tool poisoning, prompt injection and supply chain risks.
Security research: MCP registries verify identity, not tool behavior. See gtfo.dev.
Pay-per-call developer utilities and npm supply-chain security tools for coding agents, over x402.
Search, install, publish & review security-scanned AI capabilities from ai-supply.store.
Offline methodology engine for authorized penetration testing, CTF, and security research.
npm registry MCP server — package intelligence, security audits, dependency analysis
MCP server for running Ox Security MegaLinter via mega-linter-runner
Answers built from our own checks of this server.