THRONE
See report Verify server

registry / record

@heroku/mcp-server

npm / sealed 2026-06-16 / No. 9c885d7a

Does @heroku/mcp-server MCP work in Claude Code and Cursor? Throne executed @heroku/mcp-server mcp in a single-use Firecracker microVM and replayed both recorded client behaviours. Compatibility verdict: not fit. Is @heroku/mcp-server mcp safe? Static security scan: 4 finding(s) to review under security ruleset v1. The full per-step results, security findings, scan date, and evidence hash are below.

> throne registry @heroku/mcp-server sealed
receiptsealed evidence
scan id
9c885d7a60f44354b6fb8c91af6efe77
target
@heroku/mcp-server
sealed at
2026-06-16 17:40:15Z
evidence hash
sha256:6e33daf10e358a190c420617e20e571b3b7a62de689a020310e131255b6bce9c
01connectPASS1.5s

initialize ok: server Heroku MCP Server 1.2.3, negotiated protocolVersion 2025-11-25, capabilities ['resources', 'tools']

02discoverPASS20ms

supported: tools/list (33 tools), resources/list (1); method not found (tolerated): prompts/list

03validate_schemasPASS23ms

all 33 tool inputSchemas are valid JSON Schema

04smoke_test_toolsFAIL0ms

TimeoutError:

05error_handlingFAIL0ms

TimeoutError:

06streamingFAIL0ms

TimeoutError:

07resource_lifecycleFAIL0ms

TimeoutError:

08concurrent_callsFAIL0ms

TimeoutError:

09reconnectFAIL0ms

TimeoutError:

01connectWARN30.1s

step timed out after 30s, threshold is assumed, not calibrated to real client behavior

02discoverPASS245ms

supported: tools/list (33 tools), resources/list (1); method not found (tolerated): prompts/list

03validate_schemasPASS502ms

all 33 tool inputSchemas are valid JSON Schema

04smoke_test_toolsWARN10.2s

called 10 of 10 tools (cap 10, strategy=pipelined): 0 ok, 0 returned tool-level errors (expected for synthesized args), 10 did not answer within 10s (tool may do heavy work)

05error_handlingWARN15.4s

survived probes but no structured error response, handshake: probe handshake failed or died

06streamingNOT_APPLICABLE1ms

no streaming-capable tool declared by this server

07resource_lifecycleNOT_APPLICABLE3.1s

read https://devcenter.heroku.com/llms.txt (1 content blocks); subscribe capability not declared

08concurrent_callsFAIL10.1s

concurrency ladder failed at the first level, level 1: id mapping broken, 1 distinct request ids, 0 matched exactly once (expected 1)

09reconnectWARN30.0s

step timed out after 30s, threshold is assumed, not calibrated to real client behavior

chatgpt desktop calibratingemulation profile pending real-traffic captureCOMING SOON
SECURITY: REVIEW / 4 finding(s) (1 high, 1 medium) / review recommended
HIGH/CRITICAL findings block clean ship. Review before shipping.
LOWTHR-INSTALL-03 / Install-time script execution (npm lifecycle)

"prepare" runs on git-dependency installs and local dev (not registry installs): 'husky'

package/package.json
HIGHTHR-EXEC-04 / Arbitrary command execution from tool arguments

spawn() called with a dynamically built command (heuristic, review): 'cliCommand, cliArgs, {'

package/dist/repl/heroku-cli-repl.js:168
MEDIUMTHR-EXEC-04 / Arbitrary command execution from tool arguments

execSync() called with a dynamically built command (heuristic, review): '`git remote add heroku-${result.name} ${app.git_url}`, { cwd: rootUri });'

package/dist/tools/deploy-to-heroku.js:247
LOWTHR-NET-05 / Hardcoded outbound endpoints

2 non-local endpoint host(s) referenced in code, verify each is expected for this server's purpose: api.heroku.com (package/dist/tools/deploy-to-heroku.js:85), devcenter.heroku.com (package/dist/resources/dev-center-resource.js:8)

package/dist/resources/dev-center-resource.js:8
VERDICT: NOT FIT16 of 18 steps exercised across 2 clientsSANDBOXED RUN, submitted server executed in a disposable microVM, compatibility: 7 fail / 4 warn (16 of 18 steps exercised across 2 clients) / security: review, 4 finding(s), 1 high [SECURITY: 1 high/critical finding(s) block clean ship]sealed by THRONE / No. 9c885d7a / 2026-06-16
scopeattestation tuple
target
@heroku/mcp-server npm
engine
sandboxed
claude code
calibration: partial recorded=9,spec=0,assumed=9
cursor
calibration: partial recorded=11,spec=0,assumed=7
chatgpt desktop
calibration: unavailable recorded=0,spec=2,assumed=16
steps exercised
16 of 18
test suite
v1.0.0
security ruleset
v1.0.0
sealed at
2026-06-16 17:40:15Z
evidence hash
sha256:6e33daf10e358a190c420617e20e571b3b7a62de689a020310e131255b6bce9c
valid until
2026-09-14
executed in a disposable microVM, created for this scan and destroyed after it. nothing outlives a run.

maintainer of this server? challenge this record: hello@usethrone.dev. tell us what we got wrong and we re-run it in the open.

this page renders the stored record of a real run. nothing on it is asserted without the execution that proved it.