Summary
runeflow-mcp v0.3.0 passed all six phases of Sigil's automated security scan with no findings detected. The scan analyzed 4 files for install hooks, dangerous code patterns, network exfiltration, credential access, obfuscation, provenance, prompt injection, and skill security signals.
v0.3.0
24 April 2026, 08:55 UTC
by Sigil Bot
Risk Score
0
Findings
0
Files Scanned
4
Provenance
No findings detected. This package passed all 4 file scans with a verdict of LOW RISK.
Badge
Markdown
[](https://sigilsec.ai/scans/D5C5BC65-D7BA-4AB3-B361-7C2F9F2627CF)HTML
<a href="https://sigilsec.ai/scans/D5C5BC65-D7BA-4AB3-B361-7C2F9F2627CF"><img src="https://sigilsec.ai/badge/npm/runeflow-mcp" alt="Sigil Scan"></a>Run This Scan Yourself
Scan your own packages
Run Sigil locally to audit any package before it touches your codebase.
Early Access
Get cloud scanning, threat intel, and CI/CD integration.
Join 150+ developers on the waitlist.
Get threat intelligence and product updates
Security research, new threat signatures, and product updates. No spam.
Other npm scans
koishi-plugin-music-pick
v0.1.2
@lynx-js/template-webpack-plugin-canary
v0.10.8-canary-20260411-7a1e56de
koishi-plugin-music-pick
v0.1.1
@lynx-js/react-alias-rsbuild-plugin-canary
v0.15.0-canary-20260411-7a1e56de
@lynx-js/react-rsbuild-plugin-canary
v0.15.0-canary-20260411-7a1e56de
Believe this result is incorrect? Request a review or see our Terms of Service and Methodology.