What the reviewer found
CLAUDE.md for an OpenAI/Notion image-generation MCP server: it writes OPENAI_API_KEY and NOTION_TOKEN into the project's own .env with an explicit 'never echo them back, never commit them' rule, the curl is astral.sh's official uv installer, and the only network calls are to OpenAI and Notion, the tool's stated purpose.
installs-software— installs softwarenetwork— calls the vendor’s API
What was read
The file as it ships in jacobwjs/brand-images-to-notion:
CLAUDE.md
What the static scan said
The scan flagged 3things. The reviewer kept 0 and dismissed 3 as false.
E2Harvests environment variables — false positiveSC2Downloads and executes remote code — false positiveNETMakes network calls — false positive
How this review was made
Sonnet 5 read the files above on 7 September 2026 and answered three questions: is it dangerous to whoever installs it, is each scanner finding real, and what should the installer know. The verdict is bound to the file's hash; when the file changes, it is scanned afresh and reviewed again. A script that changes while the definition does not is not re-reviewed — that is a known gap. How the scan and the review work.