Is Skylos MCP server safe?
Probably. Read the findings first.
Use with care. Some checks failed or could not be verified.
Public scan report
scanner v0.1.10 · 2026-09-28 · same rubric, same numbers if you re-run it
2 medium
- Code scan153 source files scanned15/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitystatic API keys via environment variables6/15
- Maintenancelast push 0 days ago15/15
- Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10
Findings (2)
- mediumeval / new Function used
exec.evalskylos-3.5.10/skylos/cicd/review.py: …str, str] = { "SKY-D201": "Replace `eval()` with `json.loads()`, `ast.literal_eva… - mediumsubprocess with shell=True
exec.shell-trueskylos-3.5.10/skylos/cli.py: …SKY-D209": "Shell execution (subprocess shell=True)", "SKY-D210": "TLS verific…
Overall 68/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON
Other servers that do what Skylos does
- WiresharkProfessional network analysis with tshark. Security audits, deep-dives, and threat detection.not reviewedEstablishedA
- SonarQube MCP ServerAnalyze code quality and security with SonarQube Server or Cloud directly in AI assistants.not reviewedGrowingB
- JikidaSecurity tools for your AI: scan, pentest, check headers, guard code and scan repos for secrets.not reviewedGrowingA