Skip to content

MCP servers › io.github.TKMD › reftrixmcp

MCP server · registry snapshot 2026-10-04

io.github.TKMD/reftrixmcp

Web design analysis with 26 MCP tools: layout, motion, quality, semantic search via pgvector — the publisher's description

version 0.1.8TypeScriptAGPL-3.0-onlystandard input/output

Summary

io.github.TKMD/reftrixmcp is a local MCP server listed in the official MCP registry at version 0.1.8. We have not tested it. It requires a credential (a key or token) that the publisher marks as required. We never fill in credentials, so we did not start it.

Key facts

Runs
local package
Transport
standard input/output
Package
npm · listed version behind the latest release
License
AGPL-3.0-only
Dependencies
0 critical, 4 high advisories
Repository
public
Last tested
not tested

Worth knowing before you connect it

  • The registry lists 0.1.8; 0.6.0 is newer (5 releases).
  • 0 critical and 4 high advisories in its dependencies (as resolved on 2026-10-08).

Each line comes from a section below, with its source and date.

How fresh this is

Live-tested
no
Last tested
not tested
Registry data
snapshot 2026-10-04
Package and repository
checked 2026-10-06

Security testing

Has it been tested?

Feature #1

It requires a credential (a key or token) that the publisher marks as required. We never fill in credentials, so we did not start it.

Required input the publisher declares: DATABASE_URL (secret).

What it is

Does the registry listing match what we found?

Feature #6

The registry verifies a package once, when it is published, and does not re-check it. A difference below is about the listing, not a judgement of the publisher.

Registry saysWe foundResultSource · date
Version 0.1.8 on npmExists and can be installedmatchesnpm · 2026-10-06
Repository github.com/TKMD/ReftrixMCPOpens publiclymatchesapi.github.com · 2026-10-06

Can it be installed, and is it up to date?

Version pin · advisories

Listed version

Registry lists
0.1.8
Latest stable
0.6.0
Status
behind the latest release (5 releases, 112 days)
Withdrawn
no

Source: registry.npmjs.org · 2026-10-06. About the version the registry lists; a manual install may resolve to a different one.

Dependency advisories

critical0high4moderate4low0

Counted in the full dependency tree as resolved on 2026-10-08 (npm audit). Bars share one scale. The package itself has no known vulnerability (OSV.dev).

Integrity, provenance, license

Integrity
sha512-Arzi4jY5FCFLQzDG+…
Signature
signed
License
AGPL-3.0-only

Source: the package registry · 2026-10-06.

Usage

Downloads
149 in the last month

Source: api.npmjs.org · 2026-10-06.

Who made it?

Feature #7 · lineage

Facts about the publisher. We do not turn them into a trust score.

Namespace
io.github.TKMD
GitHub owner
a personal account (TKMD)
Build record
signed
Repository
github.com/TKMD/ReftrixMCP
Stars
2
Repository age
181–365 days
Last push
0–30 days ago
Archived
no

Source: the registry entry and api.github.com · 2026-10-06.

Choosing

Common questions about io.github.TKMD/reftrixmcp

Answered from the data above

Has io.github.TKMD/reftrixmcp been security tested?

Not yet. It requires a credential (a key or token) that the publisher marks as required. We never fill in credentials, so we did not start it.

Is the listed version current?

No. The registry lists 0.1.8; the latest stable release on npm is 0.6.0.

Where is the source code of io.github.TKMD/reftrixmcp?

In github.com/TKMD/ReftrixMCP, which opens publicly.

Reference

How is it classified?

18 fields

One value per field, each with its source. Fields written by AI models are marked. A field with no value says why.

TopicAI-classified
no value
No value: the two AI models (Gemini and Claude) disagreed, so neither answer is shown.
Pricing modelAI-classified
not checked
no website in the registry entry
Programming language
TypeScript
api.github.com · 2026-10-08
Hosting type
local package
registry · 2026-10-04
MCP capability
not checked
not read (no session)
Transport
standard input/output
registry · 2026-10-04
Required credentials
requires a secret
registry · no declaration is not a guarantee
Package registry
npm
registry · 2026-10-04
Freshness
181–365 days
registry updatedAt · 2026-10-04
Lifecycle status
active
registry · 2026-10-04
License class
copyleft
package registry · 2026-10-06
Integrity hash
declared (sri)
package registry · 2026-10-06
Signature / provenance
signed
package registry · 2026-10-06
Dependency advisories
high
npm audit · 2026-10-08
Popularity
149 downloads a month
package registry · 2026-10-06
Publisher signals
owner: a personal account · repository age: 181–365 days · stars: 0–9 · build record: signed
api.github.com · 2026-10-06
Maintenance
active
api.github.com · 2026-10-06
Environment
your machine
where it runs, from the hosting type

“Not stated” means the source did not state it; “does not apply” means it does not apply to this kind of server; “our limit” means our own lookup failed.

Cite or correct this page

Sources and corrections

Suggested citation

ProtocolProbe. “io.github.TKMD/reftrixmcp: MCP server record.” Data checked 2026-10-06. https://protocolprobe.com/mcp/servers/io.github.TKMD/reftrixmcp

Quoting is welcome with a link and the check date. Figures are valid for the date shown.

Something wrong, or is this yours?

If a fact here is wrong, tell us and we will re-check it. If you operate this server, you can authorize a full test.

Write to hello@protocolprobe.com · corrections log · methodology