Is Hythe MCP server safe?
Probably. Read the findings first.
Use with care. Some checks failed or could not be verified.
Public scan report
scanner v0.1.9 · 2026-09-20 · same rubric, same numbers if you re-run it
1 medium
- Code scan124 source files scanned20/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitystatic API keys via environment variables6/15
- Maintenancelast push 15 days ago15/15
- Maintainer identitynamespace and repository owner differ4/10
Findings (1)
- mediumeval / new Function used
exec.evaldist/memory/sqlite-vec-client.js: …(moduleName) { const importer = new Function('m', 'return import(m);'); retur…
Overall 69/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON
Other servers that do what Hythe does
- Hicortex — AI Fleet MemoryShared fleet memory for AI agents: nightly self-correction, recall every prompt (supported agents).not reviewedGrowingC
- AISIX AI GatewaySelf-hosted AI gateway that governs MCP servers, LLM traffic, and A2A agents behind one endpointnot reviewedGrowingA
- HOL GuardLocal-first AI agent security evidence and approval workflows through HOL Guard's stdio MCP server.not reviewedEstablishedA