Is Hive Intelligence MCP safe?
Yes, with the usual care.
Safe to use. Minor gaps such as a missing repository or slower maintenance.
What to know before installing
- highShell command built from a string (injection risk)
Public scan report
scanner v0.1.2 · 2026-09-18 · same rubric, same numbers if you re-run it
1 high1 medium
- Code scan98 source files scanned8/25
- Live reliabilityremote reachable in 1735ms20/20
- Tool poisoning8 tool descriptions checked15/15
- Auth qualityAPI key sent as a header8/15
- Maintenancelast push 0 days ago15/15
- Maintainer identitynamespace and repository owner differ; GitHub account older than a year; website matches verified namespace8/10
Findings (2)
- highShell command built from a string (injection risk)
exec.shell-concatbuild/open-CAEDG67G.js: …) === "win32" ? "start" : "xdg-open"; exec(`${cmd} ${url}`, (err) => { if (err) process.s… - mediumeval / new Function used
exec.evalbuild/server.js: …e) return; await dependencies.redis.eval( `if redis.call("GET", KEYS[1]) ==…
Overall 74/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON