Is OpenGrok MCP Server safe?
Probably. Read the findings first.
Use with care. Some checks failed or could not be verified.
What to know before installing
- highShell command built from a string (injection risk)
Public scan report
scanner v0.1.3 · 2026-09-19 · same rubric, same numbers if you re-run it
1 high1 medium
- Code scan4 source files scanned8/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitystatic API keys via environment variables6/15
- Maintenancelast push 3 days ago15/15
- Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10
Findings (2)
- highShell command built from a string (injection risk)
exec.shell-concatout/server/main.js: …new Av(t?.location??":memory:"),this.#n.exec(` PRAGMA journal_mode = WAL; PRAGMA synchronous = NORMAL; PRAGMA temp_store = memory; PRAGMA optimize; CREATE TABLE IF NOT EXISTS cacheInterceptorV${Nn} ( -- Data specific to us id INTEGER PRIMARY KEY AUTOINCREMENT, url TEXT NOT NULL, method TEXT NOT NULL, -- Data returned to the interceptor body BUF NULL, deleteAt INTEGER NOT NULL, statusCode INTEGER NOT NULL, statusMessage TEXT NOT NULL, headers TEXT NULL, cacheControlDirectives TEXT NULL, etag TEXT NULL, vary TEXT NULL, cachedAt INTEGER NOT NULL, staleAt INTEGER NOT NULL ); CREATE INDEX IF NOT EXISTS idx_cacheInterceptorV${Nn}_getValuesQuery ON cacheInterceptorV${Nn}(url, method, deleteAt); CREATE INDEX IF NOT EXISTS idx_cacheInterceptorV${Nn}_deleteByUrlQuery ON cacheInterceptorV${Nn}(deleteAt); `),this.#r=this.#n.pr… - mediumeval / new Function used
exec.evalout/server/main.js: …&&(A=this.opts.code.process(A,e));let g=new Function(`${cu.default.self}`,`${cu.default.scope…
Overall 57/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON
Other servers that do what OpenGrok MCP Server does
- GEO Tracker by DigestSEOTrack brand citations across five AI search engines. Free OSS; optional EUR 99 client-ready audit.not reviewedEstablishedA
- SocraticodeMCP server for enterprise local codebase indexing, semantic search, and code dependency graphs.not reviewedEstablishedC
- WebSearch MCP ServerZero-API-key MCP search server: multi-engine web/academic search, PDF parsing, secure web fetchnot reviewedGrowingA