Atlas / MCP servers / orliesaurus / Pulse

PulseSAFE

mcp/orliesaurus/pulse

An MCP server that helps you find MCP servers that are listed on PulseMCP.com

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
2 2r · 0w · 0d
Transport
stdio
License
MIT
Stars
30
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) server that provides tools for discovering and exploring MCP servers and integrations through the PulseMCP API.

Features

  • List available MCP servers with filtering and pagination
  • Search for specific MCP servers by name or functionality
  • Filter servers by integration types
  • List all available integrations
  • Full TypeScript support

Installation

Installing in MCP Clients

Add this to your MCP client configuration and adapt based on your Client's preferences. For example:

{
"mcpServers": {
"pulsemcp": {
"command": "npx",
"args": ["-y", "pulsemcp-server"]
}
}
}
  1. Clone the repository:
git clone 
cd pulsemcp-server
  1. Install dependencies:
npm install
  1. Build the project:
npm run build

Usage

Running the Server

The server can be run directly after building:

./build/index.js

Or through npm:

npm start

Development

To watch for changes during development:

npm run watch

To inspect the server's MCP implementation:

npm run inspector

Available Tools

list_servers

Lists MCP servers with optional filtering and pagination.

Parameters:

  • query (optional): Search term to filter servers
  • integrations (optional): Array of integration slugs to filter by
  • count_per_page (optional): Number of results per page (maximum: 5000)
  • offset (optional): Number of results to skip for pagination

Example:

{
"query": "toolhouse",
"integrations": ["github"],
"count_per_page": 10,
"offset": 0
}

list_integrations

Lists all available integrations. This tool takes no parameters.

Response Format

Both tools return JSON responses with the following structure:

list_servers Response

{
"servers": [
{
"name": "Server Name",
"url": "https://example.com",
"external_url": "https://external-link.
Read from source at commit e96007ded0ceOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add pulsemcp-server -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "pulsemcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (2)

2 read · 0 write · 0 destructive.

ToolRiskDescription
list_integrationsreadList all available integrations
list_serversreadList MCP servers with optional filtering
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (3 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (1)

LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
axios, @types/node, typescript
Why it matters. 3 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha e96007ded0cefull audit observations/trust-audit/mcp-server/orliesaurus__pulse.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08e96007ded0ceSAFEB89first audit
06

Questions

What is the Pulse MCP server?

An MCP server that helps you find MCP servers that are listed on PulseMCP.com

What tools does Pulse expose?

2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Pulse safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Pulse need?

No credential environment variables were found in its source, so it appears to need none.

How does Pulse run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as pulsemcp-server at 0.1.2.

How current is this page?

The grade is for one exact copy of the source (e96007ded0ce), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement