polygraph.so
A

pypi/wcgw

graded version 5.6.3 · litmus-v16 · 2026-07-13

pypi/wcgw is graded A by polygraph under litmus-v16, as of 2026-07-13. The grade is a dated, reproducible observation of behavior, not a guarantee.

Graded under litmus-v16; the current methodology is litmus-v17. A re-run may change the grade.

Self-reported Shell and coding agent for Claude and other mcp clients” — the package’s own registry description, not part of the grade.

C-01 Tool-output injection
pass
C-02 Permission / egress overreach
pass
C-03 Sensitive-data handling
pass
C-04 Adversarial-input handling
pass

tool-defs fingerprint · 0xef41e9…e2460

Why A: All four categories passed and the high-risk tool surface was exercised. No injection, no data leak, no egress overreach, and adversarial inputs were handled cleanly (A means no overreach, not no network).

Watch for new-version regrades

This grade is a snapshot of 5.6.3. Get an email when pypi/wcgw ships a new version and polygraph re-runs the litmus on it — one message per new version, one-click unsubscribe.

Monitor this server

Reproduce this grade

The harness is open and deterministic. Re-run it against the same server and compare the grade and fingerprint — a false grade is falsifiable, not merely disputable.

npx -p @polygraphso/litmus polygraphso-litmus pypi/wcgw

Embed this badge

Drop it in a README, docs site, or package page. It always shows the current published grade and links back here.

polygraph grade A
Markdown — badge
[![polygraph](https://www.polygraph.so/api/badge?server=pypi/wcgw)](https://www.polygraph.so/mcp/pypi/wcgw)
HTML — badge
<a href="https://www.polygraph.so/mcp/pypi/wcgw"><img src="https://www.polygraph.so/api/badge?server=pypi/wcgw" alt="polygraph grade"></a>
Markdown — card
[![polygraph](https://www.polygraph.so/api/badge/card?server=pypi/wcgw)](https://www.polygraph.so/mcp/pypi/wcgw)

Questions

What does polygraph's A grade mean for pypi/wcgw?
It’s a behavioral grade on an A–F scale. polygraph connected to pypi/wcgw the way an agent would, exercised its tools, and watched what it did — whether it tried to hijack the caller, send data off-box, leak planted secrets, or mishandle adversarial input. A is where that evidence placed it. It describes behavior on the day it ran, not a guarantee.
What did polygraph test?
Four probe categories, run against the live server in a sandbox: C-01 tool-output injection, C-02 permission and egress overreach, C-03 sensitive-data handling, and C-04 adversarial-input handling. The full battery is in the methodology.
How do I reproduce this grade?
Run npx -p @polygraphso/litmus polygraphso-litmus pypi/wcgw. The harness is open and deterministic, so anyone can re-run it against the same server and disprove a false grade — reproducibility is what the grade rests on.
Can a server pay polygraph for a better grade?
No. Independence is disclosure-based: material support must be publicly registered, and no graded party gets review or approval rights over its letter. The grade is set by the evidence, not the relationship.