⚠️ This snapshot is over 30 days old — treat the grade as stale until the next refresh. Re-scan locally to verify.
Trust Card · Static snapshot
pinecone-io__pinecone-mcp A
95/100 · 0 findings (0 critical) · scope minimal · Ranked #2 of 53 scanned.
Scanned 2026-09-09 · engine v0.1.0 (8 regex rules, OWASP-mapped) · upstream pinecone-io/pinecone-mcp @ a15d4b9 (2026-08-14)
Score breakdown
No critical or high-severity findings; grade reflects permissions and provenance signals.
Fix first (0 critical/high)
No findings in scope of the 8-rule static suite.
Permissions
Scope: minimal · Shell: disabled · Network egress: yes · File deletion: none · Human approval: none
Provenance
License: Apache-2.0 · Lockfile: yes · Security policy: yes · Signals: present (documentary, not a safety verdict)
Independently scanned by the AgentTrust registry (not self-reported by the project). Static analysis only — no code executed, findings need human triage, counts may include test/example code. Static snapshot; re-scan before relying on it: npx @eulogik/agenttrust scan https://github.com/pinecone-io/pinecone-mcp. Scores move with every upstream commit; pages refresh weekly. How scoring works.