Is MCP Server safe?
Probably. Read the findings first.
Use with care. Some checks failed or could not be verified.
Public scan report
scanner v0.1.9 · 2026-09-20 · same rubric, same numbers if you re-run it
3 medium
- Code scan92 source files scanned10/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancelast push 15 days ago15/15
- Maintainer identityregistry namespace matches repository owner7/10
Findings (3)
- mediumnpm install lifecycle script present
install.script - mediumeval / new Function used
exec.evaldist/src/handlers/cache.js: …y:e,token:a}=p;return await(await u(n)).eval('if redis.call("get",KEYS[1])==ARGV[1] t… - mediumnpm install lifecycle script present
install.scriptpackage.json: …js && node scripts/bauabdruck.mjs", "postinstall": "node scripts/postinstall.js", "dev…
Overall 68/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON
Other servers that do what MCP Server does
- VestigeLocal-first memory for AI agents that reaches backward to find a failure's root cause.not reviewedEstablishedB
- Deja Vudeja-vu: local memory over the session histories of thirty-three coding agents.not reviewedEstablishedA
State Memory MCPDeterministic, persistent graph server for tracking workflow state, decisions, and blockers.not reviewedEstablishedA