registry / record
@apify/actors-mcp-server
Does @apify/actors-mcp-server MCP work in Claude Code and Cursor? Throne executed @apify/actors-mcp-server mcp in a single-use Firecracker microVM and replayed both recorded client behaviours. Compatibility verdict: needs your API key. Is @apify/actors-mcp-server mcp safe? Static security scan: 7 finding(s) to review under security ruleset v1. The full per-step results, security findings, scan date, and evidence hash are below.
> throne registry @apify/actors-mcp-server
sealed
- scan id
- 9462b327c93b4fd897c93cac7075c0fb
- target
- @apify/actors-mcp-server
- sealed at
- 2026-06-16 17:16:30Z
- evidence hash
- sha256:d94b55c55db3ea15aa8daa2490d1cad2e6b1bf184f25774db138930324ad7d63
server never launched: server process exited with code 1 before the MCP handshake, stderr: [31mERROR[39m APIFY_TOKEN is required but not set in the environment variables or in ~/.apify/auth.json APIFY_TOKEN is required but not set in the environment variables or in ~/.apify/auth.json
not run, server never launched
not run, server never launched
not run, server never launched
not run, server never launched
not run, server never launched
not run, server never launched
not run, server never launched
not run, server never launched
server never launched: server process exited with code 1 before the MCP handshake, stderr: [31mERROR[39m APIFY_TOKEN is required but not set in the environment variables or in ~/.apify/auth.json APIFY_TOKEN is required but not set in the environment variables or in ~/.apify/auth.json
not run, server never launched
not run, server never launched
not run, server never launched
not run, server never launched
not run, server never launched
not run, server never launched
not run, server never launched
not run, server never launched
apiKey assigned a literal value e977… (32 chars), verify it is not a live credential
package/dist/const.d.ts:78apiKey assigned a literal value 2676… (32 chars), verify it is not a live credential
package/dist/const.d.ts:86apiKey assigned a literal value 8784… (32 chars), verify it is not a live credential
package/dist/const.d.ts:95apiKey assigned a literal value e977… (32 chars), verify it is not a live credential
package/dist/const.js:96apiKey assigned a literal value 2676… (32 chars), verify it is not a live credential
package/dist/const.js:106apiKey assigned a literal value 8784… (32 chars), verify it is not a live credential
package/dist/const.js:11719 non-local endpoint host(s) referenced in code, verify each is expected for this server's purpose: 916ec26e2f0abda151403acb5d8370c7 (package/dist/instrument.js:21), api.apify.com (package/dist/apify_client.js:12), apify-image-uploads-prod.s3.amazonaws.com (package/dist/resources/widgets.d.ts:12), apify-image-uploads-prod.s3.us-east-1.amazonaws.com (package/dist/resources/widgets.d.ts:12), apify.com (package/dist/const.d.ts:102), console-securitybyobscurity.apify.com (package/dist/const.d.ts:106), console.apify.com (package/dist/const.d.ts:104), crawlee.dev (package/dist/const.d.ts:101), developers.openai.com (package/dist/resources/widgets.js:28), docs.apify.com (package/dist/const.d.ts:101), docs.apify.com.evil.com (package/dist/tools/common/fetch_apify_docs.js:33), fonts.googleapis.com (package/dist/resources/widgets.d.ts:12), fonts.gstatic.com (package/dist/resources/widgets.d.ts:12), host (package/dist/mcp/actors.d.ts:15), images.apifyusercontent.com (package/dist/resources/widgets.d.ts:12)
package/dist/apify_client.js:12- target
- @apify/actors-mcp-server npm
- engine
- sandboxed
- claude code
- calibration: partial recorded=9,spec=0,assumed=9
- cursor
- calibration: partial recorded=11,spec=0,assumed=7
- chatgpt desktop
- calibration: unavailable recorded=0,spec=2,assumed=16
- steps exercised
- 18 of 18
- test suite
- v1.0.0
- security ruleset
- v1.0.0
- sealed at
- 2026-06-16 17:16:30Z
- evidence hash
- sha256:d94b55c55db3ea15aa8daa2490d1cad2e6b1bf184f25774db138930324ad7d63
- valid until
- 2026-09-14
maintainer of this server? challenge this record: hello@usethrone.dev. tell us what we got wrong and we re-run it in the open.
this page renders the stored record of a real run. nothing on it is asserted without the execution that proved it.