Weekly security exposure profile on claimed and verified servers
Every claimed and verified server now gets a weekly static scan of its repository, shown on the server page as a security profile. The profile lists what the code reaches: network hosts, environment variables, shell and dynamic code execution, credential and agent configuration files, persistence and similar capabilities, each with a count and where we found it. From that we state an exposure level of minimal, limited, broad or extensive. It describes what the server opens up, not the maintainer; a server may need broad access to do its job. Owners see file and line examples and dependency advisories on their dashboard.