Atlas / MCP servers / tecfu / tty-table

tty-tableSAFE

mcp/tecfu/tty-table

Cross-platform terminal table (Windows, Linux, macOS). Can also run in the browser console and provide. MCP server gives your coding agent with a quick way to add text-wrapped ASCII tables to your README or other files.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
1 1r · 0w · 0d
Transport
stdio
License
MIT
Stars
310
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A TypeScript-first terminal table renderer with a compatibility-oriented factory API.

Examples

See here for complete example list

To view all example output:

$ git clone https://github.com/tecfu/tty-table && cd tty-table && npm i
$ npm run view-examples

Terminal (Static)

examples/styles-and-formatting.js

Terminal (Streaming)

$ node examples/data/fake-stream.js | tty-table --format json --header examples/config/header.js

  • See the built-in help for the terminal version of tty-table with:
$ tty-table -h

MCP server

Expose tty-table to MCP clients (Claude, IDE agents, Cursor, etc.) over stdio.

Client configuration

{
"mcpServers": {
"tty-table": {
"command": "npx",
"args": ["-y", "--package=tty-table", "tty-table-mcp"]
}
}
}

Tools

Arguments for `render_table`:

Example tool call:

{
"header": [{ "value": "name" }, { "value": "score", "align": "right" }],
"rows": [["Ada", 100], ["Grace", 98]],
"options": { "width": 40 }
Read from source at commit 41b7fe4af42dOBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add tty-table -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "tty-table": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (1)

1 read · 0 write · 0 destructive.

ToolRiskDescription
render_tableread
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (3)

LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
test/mocha.conf.js:24
exec(`COLUMNS=${pkg.defaultTestColumns} node ${element} --color=always`,
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWInsecure crypto · crypto.weak_random · CWE-327, CWE-338
examples/data/streamer.js:17
//  let random =   Math.floor(Math.random() * keys.length) + 0;
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, breakword, chalk, csv, smartwrap, strip-ansi, yargs, zod
Why it matters. 20 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 41b7fe4af42dfull audit observations/trust-audit/mcp-server/tecfu__tty-table.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0641b7fe4af42dSAFEB89first audit
06

Questions

What is the tty-table MCP server?

Cross-platform terminal table (Windows, Linux, macOS). Can also run in the browser console and provide. MCP server gives your coding agent with a quick way to add text-wrapped ASCII tables to your README or other files.

What tools does tty-table expose?

1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is tty-table safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does tty-table need?

No credential environment variables were found in its source, so it appears to need none.

How does tty-table run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as tty-table at 7.1.0.

How current is this page?

The grade is for one exact copy of the source (41b7fe4af42d), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement