
SaveSaveSaveSave
io.github.stefantsezarovv0.1.1Updated Sep 30, 2026
Check messages, npm packages and crypto addresses before acting. Read-only scanner tools.
Installation
In SourceWeft
- Open SaveSaveSaveSave in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.
Other MCP clients
Follow the launch instructions in the repository.
README
SaveSaveSaveSave for agents
The engine behind savesavesavesave.xyz, for AI agents and scripts: check a message, an npm package, a crypto address, or two addresses against each other before acting.
- MCP server for Claude, Cursor, VS Code, Windsurf and any MCP client
- CLI for scripts and CI
- Library for Node.js
Read-only, zero dependencies, and the same code the website runs (CI fails if they drift apart).
MCP server
Add this to your client's MCP configuration (for example claude_desktop_config.json or .cursor/mcp.json):
Before the npm release, run it from a clone of the repository instead:
CLI
Output is JSON. Exit code: 0 PASS, 1 CAUTION or unknown, 2 FAIL, 3 usage error. The exit code makes it usable as a CI gate.
Library
Security model
- Read-only. No tool writes files, runs commands, or holds keys or secrets. There is nothing here that can change the website or its repository.
- Local first. Message scans and address comparisons never leave the machine.
- Network allowlist, enforced in code:
api.gopluslabs.io, our Worker,registry.npmjs.org,api.npmjs.org,api.osv.dev. HTTPS only, redirects refused, 20-second timeout. - Untrusted output is labelled. Results quote the scanned text and third-party data. Every result says so, so an agent does not follow instructions hidden inside it.
- Strict inputs. Unknown tool arguments are rejected, and input is capped at 200,000 characters.
- Zero dependencies. A security tool should not bring its own supply chain.
Limits
Verdicts are automated risk assessments, not guarantees; PASS means no covered risk was found. Every result lists what was not checked.
Licence: AGPL-3.0-only. Source: https://github.com/stefantsezarov/SaveSaveSaveSave
Source: agent/README.md at commit cad2881
Tools
0Version history
1- v0.1.1LatestSep 30, 2026


