Is grim-mcp server safe?
Probably. Read the findings first.
Use with care. Some checks failed or could not be verified.
Public scan report
scanner v0.1.8 · 2026-09-19 · same rubric, same numbers if you re-run it
4 medium
- Code scan33 source files scanned; 32 source files scanned5/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancelast push 0 days ago15/15
- Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10
Findings (4)
- mediumsubprocess with shell=True
exec.shell-truepython/grim/core/fixplan.py: …fe_load(", line, count=1), False # shell=True with untrusted input -> disable shell e… - mediumeval / new Function used
exec.evalpython/grim/engines/codepatterns.py: …\beval\s*\("), "high", "eval() usage", "eval executes arbitra… - mediumsubprocess with shell=True
exec.shell-truegrim-mcp-0.6.2/src/grim/core/fixplan.py: …fe_load(", line, count=1), False # shell=True with untrusted input -> disable shell e… - mediumeval / new Function used
exec.evalgrim-mcp-0.6.2/src/grim/engines/codepatterns.py: …\beval\s*\("), "high", "eval() usage", "eval executes arbitra…
Overall 62/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON
Other servers that do what grim-mcp does
- npm Registry MCP Servernpm registry MCP server — package intelligence, security audits, dependency analysisnot reviewedGrowingB
DraugrSecurity scanning for AI agents: SAST, SCA, secrets, IaC, DAST, ranked by real risk.not reviewedGrowingA- Connection String Secret Audit26 rules and 32 safe-replacement snippets for hardcoded connection strings, keys and kubeconfigs acrnot reviewedGrowingA