Mmcp.market

Is Projscan MCP server safe?

Yes, with the usual care.

B80/100grade B

Safe to use. Minor gaps such as a missing repository or slower maintenance.

No critical or high findings in the latest scan.

Public scan report

scanner v0.1.9 · 2026-09-25 · same rubric, same numbers if you re-run it

1 medium
  • Code scan1500 source files scanned20/25
  • –Live reliabilityno gateway calls yet and no remote to proben/a
  • –Tool poisoningtools not inspected (local package is not executed); not countedn/a
  • Auth qualitylocal package, no credentials required12/15
  • Maintenancelast push 67 days ago12/15
  • Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10

Findings (1)

  • mediumeval / new Function usedexec.eval
    dist/core/pluginDx.js: …m './plugins.js'; const dynamicImport = new Function('specifier', 'return import(specifier)')…
Overall 80/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Other servers that do what Projscan does

  • Basic Memory
    Local-first knowledge management with bi-directional LLM sync via Markdown files.
    C
  • Agent-Native Chat
    Minimal chat-first app with durable threads, actions, and the app-agent loop
    A
  • Agent Recall
    Correction-first agent memory. Precision KPI tracks if agents heed warnings. 5 layers, local-only.
    A

Projscan reviews, tools and install