nova-act-mcp-server — security audit

nova-act-mcp-server: trust score 25/100 — 1 capability surface.

Trust score

25

Grade F

Risk flags

  • Community-authored

    Maintained by madtank. Confirm the repo and signing before installing.

Capability surface

  • Browser automation

    High risk

    Drives a real browser (Playwright, Puppeteer). Can scrape any logged-in service.

    Evidence: browser automation

Trust signals

Total trust score is the sum of these contributions. Each signal carries a fixed weight.

  • Verified by Loadout

    +0 / 20

    Not in our manually-verified set yet.

  • Official author

    +0 / 15

    Maintained by community contributors.

  • Community traction

    +0 / 20

    No star data available.

  • Public source

    +15 / 15

    Source is publicly auditable.

  • Stability

    +0 / 15

    Stability not yet assessed.

  • Capability surface

    +10 / 15

    1 high-risk capability detected.

Disclaimer

This is an automated heuristic triage. It does not replace a hand-rolled code audit. Use it to prioritise which servers deserve a deeper look — especially anything carrying high-risk capabilities like shell execution or filesystem write.