Is Log10x MCP safe?
Probably. Read the findings first.
Use with care. Some checks failed or could not be verified.
What to know before installing
- highcurl | sh in a script
Public scan report
scanner v0.1.3 · 2026-09-19 · same rubric, same numbers if you re-run it
1 high
- Code scan558 source files scanned13/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitystatic API keys via environment variables6/15
- Maintenancelast push 2 days ago15/15
- Maintainer identityregistry namespace matches repository owner; GitHub account older than a year9/10
Findings (1)
- highcurl | sh in a script
install.curl-pipebuild/lib/install-hints.js: … return { command: 'curl -fsSL https://raw.githubusercontent.com/log-10x/pipeline-releases/main/install.sh | sh -s -- --flavor runtime', do…
Overall 66/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON