Skip to content

Rule Reference

This page is generated from nw rules list --json.

RuleSeverityDocsFixSummary
mcp_secret_envcriticaldocsexternalize-secretMCP server stores a sensitive environment variable inline
mcp_secret_headercriticaldocsexternalize-secretMCP server stores a sensitive header inline
mcp_unpinned_packagehighdocspin-packageMCP server runs a package executor without an obvious pin
mcp_shell_wrapperhighdocsreplace-shell-wrapperMCP server runs through a shell wrapper
mcp_local_endpointmediumdocsmanual-reviewMCP server references a machine-local endpoint
mcp_broad_filesystemmediumdocsnarrow-filesystemMCP server can access a broad filesystem path
mcp_local_token_pathhighdocsmanual-reviewMCP server references a local credential path
mcp_server_reviewinfodocsmanual-reviewMCP server should be reviewed
mcp_unknown_commandinfodocsmanual-reviewMCP server has an unsupported command shape
config_parse_failedmediumdocsmanual-reviewNightward could not parse a config file
config_symlinkinfodocsmanual-reviewConfig file is a symbolic link

Local-first. No telemetry. No default network calls. No live config mutation.