Atlas / MCP servers / dave-london / Pare

PareSAFE

mcp/dave-london/pare

Dev tools, optimized for agents. Structured, token-efficient MCP servers for git, test runners, npm, Docker, and more.

Verdict
SAFE
Grade
C
Trust score
73 /100
Exposed tools
200 165r · 41w · 9d
Transport
stdio
License
MIT
Stars
138
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Pare

[](https://github.com/Dave-London/Pare/actions/workflows/ci.yml) [](https://codecov.io/gh/Dave-London/Pare) [](https://www.npmjs.com/package/@paretools/git) [](https://www.npmjs.com/package/@paretools/git) [](https://www.typescriptlang.org/) [](https://github.com/Dave-London/Pare/blob/main/LICENSE) [](https://nodejs.org) [](https://scorecard.dev/viewer/?uri=github.com/Dave-London/Pare) [](https://www.bestpractices.dev/projects/11962)

Reliable, structured CLI output for AI agents — no more parsing fragile terminal text.

Pare provides MCP servers that wrap common developer tools (git, npm, docker, test runners, etc.) and return clean, schema-validated JSON instead of raw terminal text. Agents get typed data they can act on directly, without brittle string parsing.

The Problem

Parsing CLI output is fragile. Raw terminal text includes ANSI escape codes, decorative headers, progress bars, locale-specific formatting, and platform differences that break agent workflows in subtle ways. An agent that works fine with git status on macOS may fail on Windows because the output format changed. A test runner's summary line might shift between versions, silently breaking a regex.

Pare eliminates this entire

Read from source at commit 6f666d56ef4aOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (npm)
claude mcp add bazel -- npx -y @paretools/[email protected]
03

Exposed tools (200)

165 read · 41 write · 9 destructive. Blast radius: 9 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
areadA
addwrite
add-packagewrite
ansible-galaxyread
ansible-inventoryread
ansible-playbookread
apiread
applywrite
archiveread
assemblereadAssembles the outputs of this project.
auditread
breadB
bazelread
biome-checkread
biome-formatread
bisectread
blackread
blameread
branchread
bugreadSomething isn
buildread
bundle-checkread
bundle-execwrite
bundle-installwrite
creadC
checkread
checkoutread
cherry-pickread
cleanread
clippyread
cmakeread
commitwrite
compose-buildread
compose-downread
compose-logsread
compose-psread
compose-upread
condaread
configread
countread
coverageread
describeread
developread
diffread
discover-toolsread
discussion-listread
docread
enhancementreadNew feature
envread
esbuildread
execwrite
featureread
findread
flake-checkread
flake-showread
flake-updatewrite
fmtread
format-checkread
gem-installwrite
gem-listread
gem-outdatedread
generateread
getread
gist-createwrite
gitleaksread
golangci-lintread
gradle-buildread
gradle-dependenciesread
gradle-tasksread
gradle-testread
hadolintread
headread
helmread
helpreadShows help.
imagesread
inforeadRuns
initreadInitializes a Terraform working directory. Downloads providers, configures backend, and prepares for plan/apply.
inspectreadShows detailed container or image information with structured state, image, and platform data.
installwriteRuns
issue-closereadCloses an issue with an optional comment and reason. Returns structured data with issue number, state, URL, reason, and comment URL.
issue-commentreadAdds, edits, or deletes a comment on an issue. Returns structured data with the comment URL, operation type, comment ID, issue number, and body echo.
issue-createwriteCreates a new issue. Returns structured data with issue number, URL, and labels applied.
issue-listreadLists issues with optional filters. Returns structured list with issue number, state, title, labels, assignees, author, creation date, and milestone.
issue-updatewriteUpdates issue metadata (title, body, labels, assignees, milestone, projects). Returns structured data with issue number and URL.
issue-viewreadViews an issue by number or URL. Returns structured data with state, labels, assignees, author, milestone, close reason, and body.
jqreadProcesses and transforms JSON using jq expressions. Accepts JSON from a file path or inline string.
label-createwriteCreates a new repository label. Returns structured data with label name, description, color, and URL.
label-listreadLists repository labels. Returns structured data with label name, description, color, and default status.
lernawriteRuns Lerna monorepo commands (list, run, changed, version) and returns structured package information.
lintreadRuns
listreadLists Go packages or modules and returns structured information.
list-packagereadRuns dotnet list package and returns structured NuGet package listings per project and framework.
logwriteReturns commit history as structured data.
log-graphreadReturns visual branch topology as structured data. Wraps
logsreadRetrieves container logs as structured line arrays.
maven-buildreadRuns
maven-dependenciesreadShows the Maven dependency tree with structured output per artifact.
maven-testreadRuns
maven-verifyreadRuns
mergewriteMerges a branch into the current branch. Supports abort, continue, and quit actions. Returns structured data with merge status, fast-forward detection, conflicts, and commit hash.
mod-tidydestructiveRuns go mod tidy to add missing and remove unused module dependencies.
mongosh-evalreadEvaluates a MongoDB expression via mongosh and returns the output.
mongosh-statsreadGets MongoDB database statistics (collections, objects, data size, storage, indexes) via mongosh.
my-labelreadA test label
mypyreadRuns mypy and returns structured type-check diagnostics (file, line, severity, message, code).
mysql-list-databasesreadLists all MySQL databases with structured output.
mysql-queryreadExecutes a MySQL query and returns structured tabular output.
network-lsreadLists Docker networks with structured driver and scope information.
nvmreadManages Node.js versions via nvm.
nxreadRuns Nx workspace commands and returns structured per-project task results with cache status.
outdatedreadRuns
outputreadShows Terraform output values from the current state. Returns structured name/value/type/sensitive data.
oxlintreadRuns Oxlint and returns structured diagnostics (file, line, column, rule, severity, message).
package-cleanreadCleans Swift package build artifacts and returns structured result.
package-initreadInitializes a new Swift package and returns structured result with created files.
package-resolvereadResolves Swift package dependencies and returns structured resolution results.
package-show-dependenciesreadShows the dependency tree of a Swift package and returns structured dependency data.
package-updatewriteUpdates Swift package dependencies and returns structured update results.
pip-auditreadRuns pip-audit and returns a structured vulnerability report.
pip-installwriteRuns pip install and returns a structured summary of installed packages.
pip-listreadRuns pip list and returns a structured list of installed packages.
pip-showreadRuns pip show and returns structured package metadata (name, version, summary, dependencies).
planreadShows the Terraform execution plan with resource change counts. Read-only.
playwrightreadRuns Playwright tests with JSON reporter and returns structured results with pass/fail status, duration, and error messages.
pm-lsreadRuns
poetryreadRuns Poetry commands and returns structured output.
postwriteMakes an HTTP POST request via curl and returns structured response data.
pr-checksreadLists check/status results for a pull request. Returns structured data with check names, states, URLs, and summary counts (passed, failed, pending).
pr-closereadCloses a pull request with an optional comment and optional branch deletion. Returns structured data with PR number, state, URL, and deleted-branch flag.
pr-commentreadAdds, edits, or deletes a comment on a pull request. Returns structured data with the comment URL, operation type, comment ID, and body echo.
pr-createwriteCreates a new pull request. Returns structured data with PR number and URL.
pr-diffwriteReturns file-level diff statistics for a pull request. Use full=true for patch content.
pr-listreadLists pull requests with optional filters. Returns structured list with PR number, state, title, author, branch, labels, draft status, and merge readiness.
pr-mergewriteMerges a pull request by number, URL, or branch. Returns structured data with merge status, method, URL, and branch deletion status.
pr-readyreadMarks a pull request as ready for review (or converts it back to draft when undo=true). Returns structured data with PR number, state, URL, and resulting draft status.
pr-reopenreadReopens a previously closed pull request, optionally with a comment. Returns structured data with PR number, state, and URL.
pr-reviewreadSubmits a review on a pull request (approve, request-changes, or comment). Returns structured data with the review event, URL, and body echo.
pr-updatewriteUpdates pull request metadata (title, body, labels, assignees, reviewers, milestone, base branch, projects). Returns structured data with PR number and URL.
pr-viewreadViews a pull request by number, URL, or branch. Returns structured data with state, checks, review decision, diff stats, author, labels, draft status, assignees, milestone, and timestamps.
prettier-formatwriteFormats files with Prettier (--write) and returns a structured list of changed files.
priorityreadHigh priority issues
psreadLists Docker containers with structured status, ports, and state information.
psql-list-databasesreadLists all PostgreSQL databases via psql with owner, encoding, and size info.
psql-queryreadExecutes a PostgreSQL query via psql and returns structured tabular output.
publishwriteRuns dotnet publish for deployment and returns structured output with output path and diagnostics.
pullreadPulls a Docker image from a registry and returns structured result with digest info.
pushwritePushes commits to a remote repository. Returns structured data with success status, remote, branch, summary, and whether the remote branch was newly created.
pyenvreadManages Python versions via pyenv.
pytestreadRuns pytest and returns structured test results (passed, failed, errors, skipped, failures).
rebasereadRebases the current branch onto a target branch. Supports abort, continue, skip, and quit for conflict resolution. Returns structured data with success status, branch info, conflicts, and rebased commit count.
redis-commandreadExecutes a Redis command via redis-cli and returns the response.
redis-inforeadGets Redis server info with structured sections (server, clients, memory, etc.).
redis-pingreadTests Redis connectivity by sending a PING command.
reflogreadReturns reference log entries as structured data, useful for recovery operations. Also supports checking if a reflog exists.
release-createwriteCreates a new GitHub release with optional asset uploads. Returns structured data with tag, URL, draft, prerelease status, and assets uploaded count.
release-listreadLists GitHub releases for a repository. Returns structured list with tag, name, draft/prerelease/latest status, publish date, creation date, and URL.
reloadreadRebuilds MCP server and sends tool list changed notification to refresh tool definitions.
remotedestructiveManages remote repositories. Supports list (default), add, remove, rename, set-url, prune, and show actions. Returns structured remote data.
removedestructiveRuns
repo-clonereadClones a GitHub repository. Returns structured data with success status, repo name, target directory, and message.
repo-viewreadViews repository details. Returns structured data with name, owner, description, stars, forks, languages, topics, license, and dates.
requestreadMakes an HTTP request via curl and returns structured response data (status, headers, body, timing).
resetdestructiveResets the current HEAD to a specified state. Supports soft, mixed, hard, merge, and keep modes. The
restorereadRuns dotnet restore to restore NuGet dependencies and returns structured results.
rollupreadRuns Rollup bundler and returns structured bundle output with errors and warnings.
rsyncwriteSyncs files between local and remote locations using rsync. Defaults to dry-run mode for safety.
ruff-checkreadRuns ruff check and returns structured lint diagnostics (file, line, code, message).
ruff-formatreadRuns ruff format and returns structured results (files changed, file list).
runwriteRuns a script or file with
run-listwriteLists workflow runs with optional filters. Returns structured list with run ID, status, conclusion, and workflow details.
run-rerunwriteRe-runs a workflow run by ID. Optionally re-runs only failed jobs or a specific job. Returns structured result with run ID, status, and URL.
run-viewwriteViews a workflow run by ID. Returns structured data with status, conclusion, jobs (with steps), and workflow details.
searchreadSearches the npm registry for packages matching a query.
secret-deletedestructiveDeletes a repository, organization, or environment GitHub Actions secret.
secret-listreadLists repository, organization, or environment secret names and metadata. Secret values are never exposed.
secret-setwriteSets a repository, organization, or environment GitHub Actions secret. Secret values are sent via stdin and never returned.
semgrepreadRuns Semgrep static analysis with structured rules and findings. Returns structured finding data with severity summary.
shellreadMakes packages available in the environment and optionally runs a command.
shellcheckreadRuns ShellCheck (shell script linter) and returns structured diagnostics (file, line, column, rule, severity, message).
showwriteShows commit details and diff statistics for a given ref.
ssh-keyscanreadRetrieves public host keys from a remote SSH server using
ssh-runwriteExecutes a command on a remote host via SSH. Returns structured output with stdout, stderr, exit code, and duration.
ssh-testreadTests SSH connectivity to a remote host. Returns whether the host is reachable and any banner message.
stashreadPushes, pops, applies, drops, shows, or clears stash entries. Returns structured result with action, success, message, and stash reference.
stash-listreadLists all stash entries with index, message, date, branch, and optional file change summary. Returns structured stash data.
state-listreadLists all resources tracked in the Terraform state. Returns resource addresses.
statsreadReturns a snapshot of container resource usage (CPU, memory, network/block I/O, PIDs) as structured data.
statusreadReturns the working tree status as structured data (branch, staged, modified, untracked, conflicts).
stylelintreadRuns Stylelint and returns structured diagnostics (file, line, column, rule, severity, message).
submodulewriteManages git submodules. Supports list (default), add, update, sync, and deinit actions. List returns structured submodule data with path, SHA, branch, and status.
tagdestructiveManages git tags. Supports list (default), create, and delete actions. List returns structured tag data with name, date, and message. Create supports lightweight and annotated tags.
taskreadRuns a named task from deno.json via
tasksreadDisplays the tasks runnable from root project.
testreadRuns
tool-areadTool A
tool-breadTool B
treereadDisplays the dependency tree for a Rust project.
trivyreadRuns Trivy vulnerability/misconfiguration scanner on container images, filesystems, or IaC configs. Returns structured vulnerability data with severity summary.
tscreadRuns the TypeScript compiler and returns structured diagnostics (file, line, column, code, message).
turboreadRuns Turborepo tasks and returns structured per-package results with cache hit/miss info.
04

Trust audit

SAFEgrade C · trust 73/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (3 observation(s))
Shell
declared (4 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
mod-tidy, remote, remove, reset, secret-delete, tag, vagrant, variable-delete, workspace
Why it matters. 9 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.binary · CWE-1104
tests/smoke/fixtures/git/log/s01-default.txt
s01-default.txt
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
tests/smoke/fixtures/git/log/s02-maxcount3.txt
s02-maxcount3.txt
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
tests/smoke/fixtures/git/log/s07-author-filter.txt
s07-author-filter.txt
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
tests/smoke/fixtures/git/log/s08-ref-main.txt
s08-ref-main.txt
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
tests/smoke/fixtures/git/show/s01-head-info.txt
s01-head-info.txt
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.hidden_file · CWE-1104
.codecov.yml
.codecov.yml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
packages/server-lint/__tests__/fixtures/stylelint-project/.stylelintrc.json
.stylelintrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
rules/.windsurfrules
.windsurfrules
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
benchmarks/v2/scripts/benchmark-v2-mutating.ts:530
description: "docker exec (ls in running container)",
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/server-security/__tests__/formatters.test.ts:164
message: "Detected use of exec()",
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/server-security/__tests__/formatters.test.ts:324
message: "Detected use of exec(). This is dangerous.",
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/server-security/__tests__/formatters.test.ts:350
expect(output).toContain("Detected use of exec(). This is dangerous.");
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/server-security/__tests__/parsers.test.ts:266
message: "Detected use of exec(). This is dangerous.",
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
packages/server-go/src/tools/mod-tidy.ts:22
return createHash("md5").update(content).digest("hex");
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
packages/server-k8s/__tests__/security.test.ts:127
expect(() => assertNoFlagInjection("/home/user/.kube/config", "kubeconfig")).not.toThrow();
Why it matters. touches a credential store
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/init/__tests__/config-writers/json-mcpservers.test.ts:5
} from "../../src/lib/config-writers/json-mcpservers.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/init/__tests__/config-writers/json-mcpservers.test.ts:6
import { memoryFs } from "../../src/lib/merge.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/init/__tests__/config-writers/json-mcpservers.test.ts:7
import { SERVERS } from "../../src/lib/servers.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/init/__tests__/config-writers/json-vscode.test.ts:2
import { writeVsCodeConfig } from "../../src/lib/config-writers/json-vscode.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/init/__tests__/config-writers/json-vscode.test.ts:3
import { memoryFs } from "../../src/lib/merge.js";
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
packages/server-http/src/__tests__/url-validation.test.ts:75
it("blocks 169.254.169.254 (link-local / cloud metadata)", async () => {
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
packages/server-http/src/__tests__/url-validation.test.ts:76
await expect(assertSafeUrl("http://169.254.169.254/")).rejects.toThrow("private/reserved IP");
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
packages/server-http/src/__tests__/url-validation.test.ts:87
it("blocks metadata.google.internal", async () => {
Why it matters. cloud metadata endpoint: the classic SSRF credential grab

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 6f666d56ef4afull audit observations/trust-audit/mcp-server/dave-london__pare.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-076f666d56ef4aSAFEC73first audit
06

Questions

What is the Pare MCP server?

Dev tools, optimized for agents. Structured, token-efficient MCP servers for git, test runners, npm, Docker, and more.

What tools does Pare expose?

200 in total: 165 read-only, 41 that write, and 9 that can delete or overwrite (mod-tidy, remote, remove, reset, secret-delete). Every one is listed on this page with its risk.

Is Pare safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it C (73/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 9 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Pare need?

No credential environment variables were found in its source, so it appears to need none.

How does Pare run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @paretools/tsconfig at 0.0.0.

How current is this page?

The grade is for one exact copy of the source (6f666d56ef4a), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement