# candor (npm · candor-ts)

Per-function effect analysis for agents: blast radius, what reaches the network, gate verdicts.

- Trust score: 83/100 (high trust)
- Change this week: +3
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-22

## Components

- npm · `candor-ts`: 83/100 (this document), [markdown](https://verifymcp.io/servers/tombaldwin-candor/candor-ts.md), [page](https://verifymcp.io/servers/tombaldwin-candor/candor-ts)

## Channel facts

- Registry: `npm`
- Package: `candor-ts`
- Version: `0.39.1`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-22.

- **Supply Chain Security**: 100/100
  - No malware found by supply-chain analysis.
  - No known CVEs affecting this package version or its production dependencies.
  - No install/post-install scripts declared.
  - 0 of 3 dependencies flagged as unhealthy.
- **Provenance & Transparency**: 97/100
  - Source repository is publicly reachable at the declared URL.
  - Cryptographically verified build provenance (signed, bound to tombaldwin/candor-ts).
  - Clear OSI-approved license ((MIT OR Apache-2.0)).
  - Actively maintained (last published 1 days ago).
  - Disclosure check failed: no security disclosure policy was found in the source repository.
- **Schema Quality & AI Usability**: 67/100
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 2732 tokens (~170/item across 16 items; 16 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 30/100
  - Stability observed for 9 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 92/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 77% of tool parameters carry a description.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - We read all 16 captured tool definition(s), and no name or description among them implies an irreversible operation.
  - An AI judge read all 17 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

## Install

### How do I install the candor MCP server?

candor runs locally as an npm package, launched with npx -y candor-ts. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add tombaldwin-candor -- npx -y candor-ts
```

### Cursor

```json
{
  "mcpServers": {
    "tombaldwin-candor": {
      "command": "npx",
      "args": [
        "-y",
        "candor-ts"
      ]
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "tombaldwin-candor": {
      "command": "npx",
      "args": [
        "-y",
        "candor-ts"
      ]
    }
  }
}
```

### Codex

```bash
codex mcp add tombaldwin-candor -- npx -y candor-ts
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "tombaldwin-candor": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "candor-ts"
      ],
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add tombaldwin-candor --command npx --arg -y --arg candor-ts
```

### Hermes

```yaml
mcp_servers:
  tombaldwin-candor:
    command: "npx"
    args: ["-y", "candor-ts"]
```

### Netclaw

```json
{
  "McpServers": {
    "tombaldwin-candor": {
      "Transport": "stdio",
      "Command": "npx",
      "Arguments": [
        "-y",
        "candor-ts"
      ]
    }
  }
}
```

### Vellum

```bash
assistant mcp add tombaldwin-candor -t stdio -c npx -a -y candor-ts
```

### Other

```json
{
  "mcpServers": {
    "tombaldwin-candor": {
      "command": "npx",
      "args": [
        "-y",
        "candor-ts"
      ]
    }
  }
}
```

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-22 (score 83, +11)

- [security improvement] Known CVEs: unverified → pass
- [functional improvement] Dependency health: unverified → 1.00

### 2026-09-21 (score 72, −10)

- [security regression] Known CVEs: pass → unverified
- [functional regression] Dependency health: 1.00 → unverified
- [functional] Package version: 0.39.0 → 0.39.1

### 2026-09-20 (score 82, 0)

- [security regression] Stability: 0.20 → unverified
- [security regression] Tool safety: pass → unverified
- [functional regression] Capabilities: pass → unverified
- [functional regression] Tool coverage: 100 → unverified
- [functional] First check of Schema quality: unverified
- [functional] Package version: 0.38.3 → 0.39.0

### 2026-09-19 (score 82, +1)

No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-17 (score 81, +16)

- [security improvement] Malware scan: unverified → pass

### 2026-09-16 (score 65, −15)

- [security regression] Stability: 0.07 → unverified
- [security regression] Malware scan: pass → unverified
- [security regression] Tool safety: pass → unverified
- [functional regression] Capabilities: pass → unverified
- [functional regression] Tool coverage: 100 → unverified
- [functional] First check of Schema quality: unverified
- [functional] Package version: 0.38.0 → 0.38.3

### 2026-09-15 (score 80, +1)

No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-14 (score 79, +15)

- [security regression] Tool safety: pass → unverified
- [security improvement] Malware scan: unverified → pass
- [security] Stability: Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet.
- [functional regression] Capabilities: pass → unverified
- [functional regression] Tool coverage: 100 → unverified
- [functional improvement] Stability: unverified → 0.03
- [functional] First check of Schema quality: unverified
- [functional] Package version: 0.37.0 → 0.38.0

## MCP tools (16)

### `candor_impact` (~88 tokens)

Backward blast radius: every effectful function that transitively calls `fn`, and which runtime entry points are downstream. Answers 'if I change this, what surfaces at runtime?' — the cheapest possible alternative to tracing callers by hand.

Input parameters:

- `fn` (string, required): the function/unit to assess
- `report` (string): report prefix (optional; defaults to $CANDOR_REPORT)

### `candor_where` (~96 tokens)

Which functions perform a given effect (e.g. Net, Db, Exec, Fs) — `directly` vs `inherited` via a callee. The effect-surface map.

Input parameters:

- `effect` (string, required): Net|Fs|Db|Exec|Env|Clock|Ipc|Log|Rand|Clipboard|Unknown
- `report` (string): report prefix (optional; defaults to $CANDOR_REPORT)

### `candor_reachable` (~57 tokens)

What the program/fleet actually DOES at runtime: effects unioned over the entry points, with how many roots reach each and via which.

Input parameters:

- `report` (string): report prefix (optional; defaults to $CANDOR_REPORT)

### `candor_path` (~73 tokens)

Forward provenance: the shortest call chain from `fn` to the nearest function that performs `effect` DIRECTLY — 'this reaches Net through WHAT?'.

Input parameters:

- `effect` (string, required)
- `fn` (string, required)
- `report` (string): report prefix (optional; defaults to $CANDOR_REPORT)

### `candor_callers` (~59 tokens)

Who calls `fn` — direct (one hop) and transitive callers over the effect-relevant call graph.

Input parameters:

- `fn` (string, required)
- `report` (string): report prefix (optional; defaults to $CANDOR_REPORT)

### `candor_show` (~68 tokens)

A function's effects (inferred = transitive, direct = own body) plus its literal surfaces (hosts/cmds/paths/tables) when present.

Input parameters:

- `fn` (string, required)
- `report` (string): report prefix (optional; defaults to $CANDOR_REPORT)

### `candor_map` (~50 tokens)

Per-module effect overview: each module's union of effects and function count. The architecture-at-a-glance.

Input parameters:

- `report` (string): report prefix (optional; defaults to $CANDOR_REPORT)

### `candor_whatif` (~300 tokens)

Hypothetically add `effect` to `fn` and report the blast radius; with `policy`, also the deny-rule violations it would cause. Pre-edit gate check. ALWAYS CHECK for the presence of `ok`, never just its value: over a report this route cannot fully evaluate, `ok` is ABSENT and `{incomplete:true, ...}` takes its place — `affected`/`violations` still ship (a partial answer beats a refusal; this tool is consulted BEFORE an edit), but neither `true` nor `false` is a claim the input licenses. The causes are the same ones `candor_gate`/`candor_unverified` disclose: `unanalyzed` (candor could not read a file of the target's own code), `outOfScope` (the peek found a denied effect outside the scan's reach), `unread` (a class the scan never opened — gated on this call's OWN `deny`/`pure` rules, since only those depend on code outside the scan's scope), and `unaskedRules` (a class something DID open, but under a narrower deny set than this policy's own).

Input parameters:

- `effect` (string, required)
- `fn` (string, required)
- `policy` (string): path to a CANDOR_POLICY file (optional)
- `report` (string): report prefix (optional; defaults to $CANDOR_REPORT)

### `candor_fix` (~417 tokens)

THE BOUNDARY FIX: when `fn` performs `effect` in a layer the policy forbids (a violation candor_whatif/candor_gate reports), compute the architectural REMEDY — not just 'the domain can't do Net', but WHERE the effect belongs and the refactor to put it there: the direct call site to hoist, the forbidden-layer functions that become pure and thread the value as a parameter, and the nearest allowed-layer caller to perform the effect ({ crossing, site, deniedSpan, hoistTo, policyAlternative }). The remedial inverse of candor_whatif. Call this INSTEAD OF guessing a fix (adding `allow` to the domain, moving the I/O one call up, threading a handle the wrong way). Advisory: it names the structure, you write the code; the gate re-scan verifies. Uses `policy` if given, else the repo's checked-in .candor/config policy (spec §3.4). ALWAYS CHECK `refused` BEFORE `crossing`: where the policy narrows on evidence this report does not carry, candor_gate REFUSES and no remedy is computed — the result is `{ fn, effect, refused:true, unevaluated:[{rule, why}] }` WITH NO `crossing` KEY, an absent key rather than `crossing:false`, because 'no boundary fix needed' is a claim and that is the one thing the tool cannot claim here (spec §3.2: an advisory verb may be LESS certain than the gate, never MORE). Re-scan so the report carries the narrowing evidence, or widen the rule; do not read the missing plan as an all-clear.

Input parameters:

- `effect` (string, required)
- `fn` (string, required)
- `policy` (string): path to a §6.2 policy file (optional; defaults to the repo's .candor/config `policy`)
- `report` (string): report prefix (optional; defaults to $CANDOR_REPORT)

### `candor_gate` (~423 tokens)

The policy verdict over this report: { ok, violations:[{rule, fn, effects, detail}] } — 'would this repo pass its architecture gate?'. Uses `policy` if given, else the repo's checked-in .candor/config policy (spec §3.4). ALWAYS CHECK `ok`, never the length of `violations`: a rule whose narrowing evidence the report does not carry is NOT EVALUATED, and then the result is `{ ok:false, refused:true, reason, unevaluated:[{rule, why}] }` WITH NO `violations` KEY — an absent key, not an empty list, because the gate is making no claim there. `unevaluated` also rides a firing verdict (a certain violation dominates a refusal). `incomplete:true` means the gate CANNOT be green, and the key beside it says which of the four causes fired: `unanalyzed` (the report declares code candor could not analyze), `outOfScope` (the producer's peek NAMED a function outside the scan's scope performing an effect this policy denies), `unread` (a class the producing scan never OPENED — its effects are absent because nothing looked, not because there are none; re-scan those sources WITH this policy), or `unaskedRules` (a class the producing scan's peek DID read, but under a deny set that does not cover this one — re-scan under THE SAME policy this tool is applying, not merely under a policy). Computed from the report — the engine's own --gate-json run is the authoritative CI form: it additionally fails an allow rule whose literal surface is INCOMPLETE (a masked/invisible endpoint), which is not a report field, so a green here can still be red in CI.

Input parameters:

- `policy` (string): path to a §6.2 policy file (optional; defaults to the repo's .candor/config `policy`)
- `report` (string): report prefix (optional; defaults to $CANDOR_REPORT)

### `candor_unverified` (~572 tokens)

PROVABLE-PURITY check (INSTANT): a `pure`/`deny <E>` policy layer PASSES a function that has no such effect — but if that function is Unknown (candor couldn't resolve one of its calls), the pass is UNVERIFIED: the Unknown could hide the very effect the rule forbids. The classic case is a fn/closure-injected 'port' — the domain reads as Unknown, so `deny Net domain`/`pure domain` clear it though it may reach Net at runtime. Returns each such function + the `deny <E> Unknown <scope>` upgrade that makes the layer PROVABLY clean. Uses `policy` if given, else the repo's checked-in .candor/config policy. ALWAYS CHECK `ok`, never the length of `unverified`: over a report declaring code candor could NOT analyze, `ok` IS ABSENT and `{incomplete:true, unanalyzed}` takes its place — a function in an unanalyzed file is missing from the report entirely, so it cannot be enumerated as an unverified pass, and an empty array there is not an all-clear (spec §3.2). `incomplete:true` also rides the three SCOPE causes, on the same terms as candor_gate: `outOfScope` (the producer's peek named a function outside the scan's scope performing a denied effect), `unread` (a class the producing scan never OPENED — re-scan those sources WITH this policy), and `unaskedRules` (a class the producing scan's peek DID read, but under a deny set that does not cover this one — re-scan under THE SAME policy this tool is applying, not merely under a policy). `ok` is ABSENT for a further reason too, and the entries that come with it are the sharpest ones: where the policy narrows on evidence this report does not carry, candor_gate REFUSES — and this verb then NAMES each function the gate could not judge, as `{fn, rule, why}` where `why` is THE MISSING EVIDENCE and never a derived class, plus the gate's own `unevaluated:[{rule, why}]`. Those entries carry no `upgrade`: whether they pass at all is the open question, so there is nothing to upgrade yet — re-scan so the report carries the evidence, or widen th…

Input parameters:

- `policy` (string): path to a §6.2 policy file (optional; defaults to the repo's .candor/config `policy`)
- `report` (string): report prefix (optional; defaults to $CANDOR_REPORT)

### `candor_containment` (~72 tokens)

Per boundary effect (Db/Net/Exec/Fs/Ipc/Clipboard): how contained it is in one architectural layer — the dispersion diagnostic (spec §6.1). Not a score; per-effect facts.

Input parameters:

- `report` (string): report prefix (optional; defaults to $CANDOR_REPORT)

### `candor_blindspots` (~75 tokens)

The Unknown SOURCES — calls the engine genuinely could not resolve (reflection, wide dispatch, fn-pointers) — ranked by how many functions inherit Unknown through each. Turns a high-Unknown report into a short worklist.

Input parameters:

- `report` (string): report prefix (optional; defaults to $CANDOR_REPORT)

### `candor_diff` (~71 tokens)

The per-function effect delta versus a baseline report: gained (introduced vs inherited) and lost effects. 'What did this change do to the effect surface?'.

Input parameters:

- `baseline` (string, required): the baseline report prefix
- `report` (string): report prefix (optional; defaults to $CANDOR_REPORT)

### `candor_gains` (~74 tokens)

The supply-chain alarm: effects the surface GAINED versus a baseline (package-level + per-function) — 'did this dependency bump add Net/Exec somewhere?'.

Input parameters:

- `baseline` (string, required): the baseline report prefix
- `report` (string): report prefix (optional; defaults to $CANDOR_REPORT)

### `candor_activity` (~183 tokens)

What the edit-time gate caught: MEASURED activity from .candor/activity.jsonl (the Stop-hook / standalone review log) — edits checked, verdicts, violations by AS-EFF code, effects introduced, largest blast radius, deepest propagation (hops), plus the most recent records. Counted from the log, no model. A missing log is an empty result (the loop isn't wired here — not an error); corrupt lines are skipped.

Input parameters:

- `limit` (number): how many recent records to return (default 5, max 50)
- `log` (string): activity log path (default .candor/activity.jsonl under --root, else beside the served report prefix, else cwd)
- `session` (string): filter to one sessionId
- `since` (string): ISO timestamp lower bound (records with no ts are kept)

## Diagnostics

Captured diagnostic sections: Provenance, Dependencies. The full working is on the page: https://verifymcp.io/servers/tombaldwin-candor/candor-ts#diagnostics

## Score history

- 2026-09-22: 83
- 2026-09-21: 72
- 2026-09-20: 82
- 2026-09-19: 82
- 2026-09-18: 81
- 2026-09-17: 81
- 2026-09-16: 65
- 2026-09-15: 80
- 2026-09-14: 79
- 2026-09-13: 64

## Common questions

### What is the candor MCP server?

candor is an MCP server listed in the public MCP registry as io.github.tombaldwin/candor. Per-function effect analysis for agents: blast radius, what reaches the network, gate verdicts. This page covers its npm package (candor-ts).

### Is the candor MCP server safe to use?

candor scores 83 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 22 September 2026. It declares no install or post-install scripts. Its build provenance is signed and verified. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the candor MCP server expose?

candor exposes 16 tools: candor_impact, candor_where, candor_reachable, candor_path, candor_callers, and 11 more. Their descriptions and schemas cost roughly 2,678 tokens of context every time the server is loaded.

### Is the candor MCP server still maintained?

candor is still listed as active in the MCP registry. We last reached this channel on 22 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- npm package: https://www.npmjs.com/package/candor-ts
- Socket report: https://socket.dev/npm/package/candor-ts
- Repository: https://github.com/tombaldwin/candor-ts
- Website: https://candor.poly.io/
- Changelog RSS feed: https://verifymcp.io/servers/tombaldwin-candor/candor-ts.xml
- Changelog JSON feed: https://verifymcp.io/servers/tombaldwin-candor/candor-ts.json
- HTML version of this page: https://verifymcp.io/servers/tombaldwin-candor/candor-ts
