Atlas / MCP servers / mapika / Portview

PortviewSAFE

mcp/mapika/portview

List ports and their processes on Linux, macOS, and Windows.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
—
Transport
stdio
License
MIT
Stars
60
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/mapika/portview/actions/workflows/ci.yml) [](https://crates.io/crates/portview) [](LICENSE)

portview lists ports and the processes using them on Linux, macOS, and Windows. It shows process names, commands, memory usage, and uptime. You can inspect a port, stop its process, or monitor changes in an interactive terminal UI.

It also supports Docker, remote hosts over SSH, and an MCP server for coding agents.

Install

Homebrew:

brew install mapika/tap/portview

Linux / macOS:

curl -fsSL https://raw.githubusercontent.com/mapika/portview/main/install.sh | sh

Windows (PowerShell):

irm https://raw.githubusercontent.com/mapika/portview/main/install.ps1 | iex

Or use cargo install portview, or download a binary from Releases.

What it does

portview                          # list all listening ports
portview 3000                     # inspect port 3000 in detail
portview node                     # find ports by process name
portview watch                    # interactive TUI with live refresh
portview watch --docker           # TUI with Docker containers as rows
portview kill 3000 --force        # terminate the process using port 3000
portview doctor                   # diagnose port conflicts and issues
portview ssh user@server          # inspect ports on a remote host
portview ssh user@server watch    # remote TUI over SSH
portview ssh user@server --agentless   # no portview needed on the remote
portview mcp                      # run as an MCP server for AI agents
Read from source at commit 487720ebbbd9OBSERVED · 2026-10-08
02

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (4)

LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
.github/workflows/release.yml:126
tar czf ../../../portview-${{ matrix.name }}.tar.gz portview
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
.github/workflows/release.yml:127
cd ../../..
LOWInventory / provenance · mcp.no_tools_extracted · CWE-1104
server.json
Why it matters. the tool list is enumerated at runtime by tools/list, not declared in source
Fix. the page says so rather than showing an empty table
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:29
curl -fsSL https://raw.githubusercontent.com/mapika/portview/main/install.sh | sh

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 487720ebbbd9full audit observations/trust-audit/mcp-server/mapika__portview.json · Report an issue / request a re-scan
03

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08487720ebbbd9SAFEB89first audit
04

Questions

What is the Portview MCP server?

List ports and their processes on Linux, macOS, and Windows.

Is Portview safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Portview need?

No credential environment variables were found in its source, so it appears to need none.

How does Portview run?

It speaks stdio, so it runs as a local process your client starts.

How current is this page?

The grade is for one exact copy of the source (487720ebbbd9), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement