Is Verdict QA safe?
Yes, with the usual care.
Safe to use. Minor gaps such as a missing repository or slower maintenance.
What to know before installing
- highWhole environment serialized (possible credential exfil)
Public scan report
scanner v0.1.2 · 2026-09-18 · same rubric, same numbers if you re-run it
1 high1 medium
- Code scan22 source files scanned8/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- Tool poisoningonly the listing description was available15/15
- Auth qualitylocal package, no credentials required12/15
- Maintenancelast push 0 days ago15/15
- Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10
Findings (2)
- mediumsubprocess with shell=True
exec.shell-trueverdict_qa_mcp-0.89.0/src/verdict_mcp/harness.py: …roc = subprocess.run(cmd, cwd=str(cwd), shell=True, capture_output=True, text=True, …
- highWhole environment serialized (possible credential exfil)
env.dumpverdict_qa_mcp-0.89.0/src/verdict_mcp/small.py: … args = ap.parse_args(argv) env = dict(os.environ) if args.env_file: if not ar…
Overall 73/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON