Mmcp.market

Is Finch MCP server safe?

Not recommended.

D49/100grade D

Hidden from default browsing. Significant findings or unreachable.

What to know before installing
  • highRemote endpoint did not respond — TypeError: fetch failed
  • highShell command built from a string (injection risk)

Public scan report

scanner v0.1.9 · 2026-09-23 · same rubric, same numbers if you re-run it

2 high
  • Code scan60 source files scanned13/25
  • Live reliabilityremote unreachable: TypeError: fetch failed0/20
  • –Tool poisoningtools not inspected (endpoint requires auth); not countedn/a
  • Auth qualityAPI key sent as a header8/15
  • Maintenancelast push 9 days ago15/15
  • Maintainer identityregistry namespace matches repository owner6/10

Findings (2)

  • highRemote endpoint did not respondreliability.unreachable

    TypeError: fetch failed

  • highShell command built from a string (injection risk)exec.shell-concat
    dist/cli.js: … try { child_process.execSync(`schtasks /Create /TN "${taskName}" /TR "${invocation}" /SC MINUTE /MO 15 /F`, { st…
Overall 49/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Safer options for the same job

  • State Memory MCP
    Deterministic, persistent graph server for tracking workflow state, decisions, and blockers.
    A
  • Knowl
    Persistent memory for Claude Code, Cursor and Codex. Facts retire when they change.
    A
  • Compartment
    Durable agentic memory, encrypted at rest. Fully offline: no network, no API key, no cloud.
    A

Finch reviews, tools and install