Is Finch MCP server safe?
Not recommended.
Hidden from default browsing. Significant findings or unreachable.
What to know before installing
- highRemote endpoint did not respond — TypeError: fetch failed
- highShell command built from a string (injection risk)
Public scan report
scanner v0.1.9 · 2026-09-23 · same rubric, same numbers if you re-run it
2 high
- Code scan60 source files scanned13/25
- Live reliabilityremote unreachable: TypeError: fetch failed0/20
- –Tool poisoningtools not inspected (endpoint requires auth); not countedn/a
- Auth qualityAPI key sent as a header8/15
- Maintenancelast push 9 days ago15/15
- Maintainer identityregistry namespace matches repository owner6/10
Findings (2)
- highRemote endpoint did not respond
reliability.unreachableTypeError: fetch failed
- highShell command built from a string (injection risk)
exec.shell-concatdist/cli.js: … try { child_process.execSync(`schtasks /Create /TN "${taskName}" /TR "${invocation}" /SC MINUTE /MO 15 /F`, { st…
Overall 49/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON
Safer options for the same job
State Memory MCPDeterministic, persistent graph server for tracking workflow state, decisions, and blockers.not reviewedEstablishedA
KnowlPersistent memory for Claude Code, Cursor and Codex. Facts retire when they change.not reviewedEstablishedA- CompartmentDurable agentic memory, encrypted at rest. Fully offline: no network, no API key, no cloud.not reviewedEstablishedA