2026-10-11 17:11 UTC

Independent use will determine whether Pharos provides reliable discovery, lockfile-based installation, dependency resolution, and vulnerability auditing for MCP servers.

state: expiredheat: lowuncertainty: highknownscott: mediummcp agentic-security developer-toolingWpnx330Pharos

What is this?

Pharos is presented in a Show HN post as an npm-like package manager for MCP servers, with an early repository commit advertising CLI commands for search, installation, package information, publishing, configuration, and health checks; the case associates it with Wpnx330. Its claimed lockfiles, dependency resolution, and vulnerability auditing address documented MCP supply-chain concerns such as untrusted servers, dependency pinning, signed releases, package vetting, and pre-installation scanning. The supplied snippets do not independently verify Pharos’s implementation or reliability, so those capabilities remain claims requiring hands-on testing.

Why it matters to Scott

Scott already frames MCP package management, reproducible dependencies, and tool supply-chain controls in “MCP as the Tool Belt Standard,” the 12-Factor Agents Framework, and Agent Provenance Stack; the radar also tracks substantially similar MCP scanning and supply-chain cases, especially Kenwea. Pharos could still matter operationally because reliable lockfiles, resolution, and auditing would directly affect his FastMCP-based MCP IP Wiki, but the supplied evidence does not yet establish that its implementation works.
ip:source.mcp-as-the-tool-belt-standard-giving-ai-agents-hands-and-eyes-ebookip:framework.12-factor-agents-frameworkip:framework.agent-provenance-stackip:concept.provenance-is-not-trustdev:technology.fastmcpdev:project.mcp-ip-wikiradar:kenwea-npm-install-sandboxradar:concept.mcp-securityradar:concept.software-supply-chainradar:concept.mcpradar:concept.agent-tooling
queries asked of Scott's wikis
  • MCP package management and tool registries
  • agent tool supply-chain security
  • lockfiles and reproducible agent environments
  • MCP server trust, signing, and provenance
  • dependency resolution for agent tooling
  • pre-install vulnerability auditing for MCP servers

Measured heat

no measured readings yet — the hourly heat pass fills this in

How the heat travelled

no chain yet — the hourly chain pass fills this in

Evidence (2) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnShow HN: Pharos – A package manager for MCP servers (like NPM, but for MCP)Wpnx33010
🟧 echo.github ⭐The earliest substantive CLI artifact is the repository commit titled “feat: PHAROS CLI — search, install, info, publish, config, health, veChris Wykel (GitHub: Wpnx330)——

Interpretation history

Decision trace