THRONE
See report Verify server

registry / record

@circleci/mcp-server-circleci

npm / sealed 2026-06-12 / No. a05b6162

> throne registry @circleci/mcp-server-circleci sealed
receiptsealed evidence
scan id
a05b6162f5d34c658b9937bc48d1cc9b
target
@circleci/mcp-server-circleci
sealed at
2026-06-12 18:22:21Z
evidence hash
sha256:e3b05f409337b4f7d378331a3d33da3f9859a9c6dcb254db0b6da2950536839c
01connectPASS1.7s

initialize ok: server mcp-server-circleci 1.0.0, negotiated protocolVersion 2025-11-25, capabilities ['resources', 'tools']

02discoverPASS12ms

supported: tools/list (17 tools); method not found (tolerated): resources/list, prompts/list

03validate_schemasPASS10ms

all 17 tool inputSchemas are valid JSON Schema

04smoke_test_toolsPASS669ms

called 10 of 10 tools (cap 10): 0 ok, 10 returned tool-level errors (expected for synthesized args)

05error_handlingPASS5.0s

structured error responses, connection survived — wrong_type_args: accepted (returned result); unknown_method: error(-32601); invalid_id: no response (silent), connection alive

06streamingPASS0ms

no streaming-capable tool declared by this server; not applicable (pass-na)

07resource_lifecyclePASS2ms

resources capability not declared; not applicable (pass-na)

08concurrent_callsWARN7ms

ladder 1/2/4/8 overlapping get_build_failure_logs calls: max_observed_stable_concurrency=8; all ids answered exactly once, but every call returned an error (tool-level isError result) — the tool may need runtime dependencies this sandbox does not provide

09reconnectPASS2.4s

transport closed and relaunched; re-handshake ok (protocolVersion 2025-11-25, first session was 2025-11-25)

01connectPASS2.4s

initialize ok: server mcp-server-circleci 1.0.0, negotiated protocolVersion 2025-11-25, capabilities ['resources', 'tools']

02discoverPASS21ms

supported: tools/list (17 tools); method not found (tolerated): resources/list, prompts/list

03validate_schemasPASS9ms

all 17 tool inputSchemas are valid JSON Schema

04smoke_test_toolsPASS357ms

called 10 of 10 tools (cap 10): 0 ok, 10 returned tool-level errors (expected for synthesized args)

05error_handlingPASS5.4s

structured error responses, connection survived — wrong_type_args: accepted (returned result); unknown_method: error(-32601); invalid_id: no response (silent), connection alive

06streamingPASS0ms

no streaming-capable tool declared by this server; not applicable (pass-na)

07resource_lifecyclePASS1ms

resources capability not declared; not applicable (pass-na)

08concurrent_callsWARN9ms

ladder 1/2/4/8 overlapping get_build_failure_logs calls: max_observed_stable_concurrency=8; all ids answered exactly once, but every call returned an error (tool-level isError result) — the tool may need runtime dependencies this sandbox does not provide

09reconnectPASS2.4s

transport closed and relaunched; re-handshake ok (protocolVersion 2025-11-25, first session was 2025-11-25)

chatgpt desktopemulation profile pending real-traffic captureCOMING SOON
SECURITY: REVIEW / 1 finding(s) / review material, not a verdict
LOWTHR-NET-05 / Hardcoded outbound endpoints

8 non-local endpoint host(s) referenced in code — verify each is expected for this server's purpose: api (package/dist/clients/circleci/index.js:15), app (package/dist/clients/circleci/index.js:21), app.circleci.com (package/dist/lib/project-detection/index.js:33), circleci.atlassian.net (package/dist/lib/project-detection/vcsTool.js:3), circleci.com (package/dist/clients/circleci/index.js:13), circlet.ai (package/dist/clients/circlet/index.js:11), gist.githubusercontent.com (package/dist/tools/runEvaluationTests/handler.js:128), runner.circleci.com (package/dist/lib/telemetry/config.js:5)

package/dist/clients/circleci/index.js:13
VERDICT: FIT TO SHIPSANDBOXED RUN — submitted server executed in a disposable microVM — compatibility: 0 fail / 2 warn across 2 clients / security: review — 1 finding(s), 0 highsealed by THRONE / No. a05b6162 / 2026-06-12
THRONE: FIT TO SHIPwear the crown

paste this in your README. it renders the live verdict and links back to this record. if a release ever breaks the verdict, the badge says so on its own.

[![THRONE: FIT TO SHIP](https://api.usethrone.dev/api/badge/%40circleci%2Fmcp-server-circleci)](https://usethrone.dev/server/circleci-mcp-server-circleci)
executed in a disposable microVM, created for this scan and destroyed after it. nothing outlives a run.

maintainer of this server? challenge this record: hello@usethrone.dev. tell us what we got wrong and we re-run it in the open.

this page renders the stored record of a real run. nothing on it is asserted without the execution that proved it.