THRONE
See report Verify server

registry / record

@modelcontextprotocol/server-everything

npm / sealed 2026-07-02 / No. f050a753

Does @modelcontextprotocol/server-everything MCP work in Claude Code and Cursor? Throne executed @modelcontextprotocol/server-everything mcp in a single-use Firecracker microVM and replayed both recorded client behaviours. Compatibility verdict: fit. Is @modelcontextprotocol/server-everything mcp safe? Static security scan: 2 finding(s) to review under security ruleset v1. The full per-step results, security findings, scan date, and evidence hash are below.

> throne registry @modelcontextprotocol/server-everything sealed
receiptsealed evidence
scan id
f050a753659840b994339cc0a4e21b22
target
@modelcontextprotocol/server-everything
sealed at
2026-07-02 09:06:31Z
evidence hash
sha256:c72d3d1fedfe0bf7b80fe2e39bae54df16e6a993046a851fa45aa9fdfd12f2c9
01connectPASS1.0s

initialize ok: server mcp-servers/everything 2.0.0, negotiated protocolVersion 2025-11-25, capabilities ['completions', 'logging', 'prompts', 'resources', 'tasks', 'tools']

02discoverPASS15ms

supported: tools/list (13 tools), resources/list (7), prompts/list (4)

03validate_schemasPASS4ms

all 13 tool inputSchemas are valid JSON Schema

04smoke_test_toolsPASS229ms

called 10 of 10 tools (cap 10, strategy=serial): 10 ok, 0 returned tool-level errors (expected for synthesized args)

05error_handlingPASS5.7s

structured error responses, connection survived, wrong_type_args: echo:accepted (returned result); get-annotated-message:accepted (returned result); get-env:accepted (returned result); get-resource-links:accepted (returned result); get-resource-reference:accepted (returned result); unknown_method: error(-32601); invalid_id: no response (silent), connection alive; oversized_input: accepted (returned result); recovery: accepted (returned result); cancellation: accepted (returned result); old_version: accepted old version 2024-10-07, negotiated 2024-10-07, server may have stale protocol handling

06streamingPASS2.0s

trigger-long-running-operation: 4 progress notifications, monotonic, final result received

07resource_lifecyclePASS18ms

read demo://resource/static/document/architecture.md (1 content blocks); subscribed 8/8 resources, unsubscribed 8/8

08concurrent_callsPASS1ms

ladder 1 overlapping echo calls: max_observed_stable_concurrency=1; all ids answered exactly once at every level

09reconnectPASS3.8s

transport closed and relaunched; re-handshake ok (protocolVersion 2025-11-25, first session was 2025-11-25)

01connectPASS2.0s

initialize ok: server mcp-servers/everything 2.0.0, negotiated protocolVersion 2025-11-25, capabilities ['completions', 'logging', 'prompts', 'resources', 'tasks', 'tools'] [request_strategy=pipelined, connection_count=2, second connection established]

02discoverPASS22ms

supported: tools/list (13 tools), resources/list (7), prompts/list (4); notes: connection 2 confirms 13 tools

03validate_schemasPASS4ms

all 13 tool inputSchemas are valid JSON Schema

04smoke_test_toolsPASS126ms

called 10 of 10 tools (cap 10, strategy=pipelined): 10 ok, 0 returned tool-level errors (expected for synthesized args)

05error_handlingPASS5.7s

structured error responses, connection survived, wrong_type_args: echo:accepted (returned result); get-annotated-message:accepted (returned result); get-env:accepted (returned result); get-resource-links:accepted (returned result); get-resource-reference:accepted (returned result); unknown_method: error(-32601); invalid_id: no response (silent), connection alive; oversized_input: accepted (returned result); recovery: accepted (returned result); cancellation: accepted (returned result); old_version: accepted old version 2024-10-07, negotiated 2024-10-07, server may have stale protocol handling

06streamingPASS2.0s

trigger-long-running-operation: 4 progress notifications, monotonic, final result received

07resource_lifecyclePASS21ms

read demo://resource/static/document/architecture.md (1 content blocks); subscribed 8/8 resources, unsubscribed 8/8

08concurrent_callsPASS7ms

ladder 1/2/4/6 overlapping echo calls: max_observed_stable_concurrency=6; all ids answered exactly once at every level

09reconnectPASS4.4s

transport closed and relaunched; re-handshake ok (protocolVersion 2025-11-25, first session was 2025-11-25)

chatgpt desktop calibratingemulation profile pending real-traffic captureCOMING SOON
SECURITY: REVIEW / 2 finding(s) / review recommended
LOWTHR-INSTALL-03 / Install-time script execution (npm lifecycle)

"prepare" runs on git-dependency installs and local dev (not registry installs): 'npm run build'

package/package.json
LOWTHR-OBF-06 / Obfuscated embedded payload

base64-like blob of 5380 chars

package/dist/tools/get-tiny-image.js:2
VERDICT: FIT18 of 18 steps exercised across 2 clientsSANDBOXED RUN, submitted server executed in a disposable microVM, compatibility: 0 fail / 0 warn (18 of 18 steps exercised across 2 clients) / security: review, 2 finding(s), 0 highsealed by THRONE / No. f050a753 / 2026-07-02
scopeattestation tuple
target
@modelcontextprotocol/server-everything npm
engine
sandboxed
claude code
calibration: partial recorded=9,spec=0,assumed=9
cursor
calibration: partial recorded=11,spec=0,assumed=7
chatgpt desktop
calibration: unavailable recorded=0,spec=2,assumed=16
steps exercised
18 of 18
test suite
v1.0.0
security ruleset
v1.0.0
sealed at
2026-07-02 09:06:31Z
evidence hash
sha256:c72d3d1fedfe0bf7b80fe2e39bae54df16e6a993046a851fa45aa9fdfd12f2c9
valid until
2026-09-30
THRONE: FITwear the crown

paste this in your README. it renders the live verdict and links back to this record. if a release ever breaks the verdict, the badge says so on its own.

[![THRONE: FIT](https://api.usethrone.dev/api/badge/%40modelcontextprotocol%2Fserver-everything)](https://usethrone.dev/server/modelcontextprotocol-server-everything)
executed in a disposable microVM, created for this scan and destroyed after it. nothing outlives a run.

maintainer of this server? challenge this record: hello@usethrone.dev. tell us what we got wrong and we re-run it in the open.

this page renders the stored record of a real run. nothing on it is asserted without the execution that proved it.