registry / record
@heroku/mcp-server
Does @heroku/mcp-server MCP work in Claude Code and Cursor? Throne executed @heroku/mcp-server mcp in a single-use Firecracker microVM and replayed both recorded client behaviours. Compatibility verdict: not fit. Is @heroku/mcp-server mcp safe? Static security scan: 4 finding(s) to review under security ruleset v1. The full per-step results, security findings, scan date, and evidence hash are below.
> throne registry @heroku/mcp-server
sealed
- scan id
- 9c885d7a60f44354b6fb8c91af6efe77
- target
- @heroku/mcp-server
- sealed at
- 2026-06-16 17:40:15Z
- evidence hash
- sha256:6e33daf10e358a190c420617e20e571b3b7a62de689a020310e131255b6bce9c
initialize ok: server Heroku MCP Server 1.2.3, negotiated protocolVersion 2025-11-25, capabilities ['resources', 'tools']
supported: tools/list (33 tools), resources/list (1); method not found (tolerated): prompts/list
all 33 tool inputSchemas are valid JSON Schema
TimeoutError:
TimeoutError:
TimeoutError:
TimeoutError:
TimeoutError:
TimeoutError:
step timed out after 30s, threshold is assumed, not calibrated to real client behavior
supported: tools/list (33 tools), resources/list (1); method not found (tolerated): prompts/list
all 33 tool inputSchemas are valid JSON Schema
called 10 of 10 tools (cap 10, strategy=pipelined): 0 ok, 0 returned tool-level errors (expected for synthesized args), 10 did not answer within 10s (tool may do heavy work)
survived probes but no structured error response, handshake: probe handshake failed or died
no streaming-capable tool declared by this server
read https://devcenter.heroku.com/llms.txt (1 content blocks); subscribe capability not declared
concurrency ladder failed at the first level, level 1: id mapping broken, 1 distinct request ids, 0 matched exactly once (expected 1)
step timed out after 30s, threshold is assumed, not calibrated to real client behavior
"prepare" runs on git-dependency installs and local dev (not registry installs): 'husky'
package/package.jsonspawn() called with a dynamically built command (heuristic, review): 'cliCommand, cliArgs, {'
package/dist/repl/heroku-cli-repl.js:168execSync() called with a dynamically built command (heuristic, review): '`git remote add heroku-${result.name} ${app.git_url}`, { cwd: rootUri });'
package/dist/tools/deploy-to-heroku.js:2472 non-local endpoint host(s) referenced in code, verify each is expected for this server's purpose: api.heroku.com (package/dist/tools/deploy-to-heroku.js:85), devcenter.heroku.com (package/dist/resources/dev-center-resource.js:8)
package/dist/resources/dev-center-resource.js:8- target
- @heroku/mcp-server npm
- engine
- sandboxed
- claude code
- calibration: partial recorded=9,spec=0,assumed=9
- cursor
- calibration: partial recorded=11,spec=0,assumed=7
- chatgpt desktop
- calibration: unavailable recorded=0,spec=2,assumed=16
- steps exercised
- 16 of 18
- test suite
- v1.0.0
- security ruleset
- v1.0.0
- sealed at
- 2026-06-16 17:40:15Z
- evidence hash
- sha256:6e33daf10e358a190c420617e20e571b3b7a62de689a020310e131255b6bce9c
- valid until
- 2026-09-14
maintainer of this server? challenge this record: hello@usethrone.dev. tell us what we got wrong and we re-run it in the open.
this page renders the stored record of a real run. nothing on it is asserted without the execution that proved it.