Is MCP Customs MCP server safe?
Probably. Read the findings first.
Use with care. Some checks failed or could not be verified.
Public scan report
scanner v0.1.9 · 2026-09-24 · same rubric, same numbers if you re-run it
2 medium
- Code scan7 source files scanned15/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancelast push 55 days ago12/15
- Maintainer identityregistry namespace matches repository owner6/10
Findings (2)
- mediumsubprocess with shell=True
exec.shell-truesrc/rules.js: …en)\([^)]*shell\s*=\s*True/g, // Python shell=True /os\.system\s*\(/g, …
- mediumeval / new Function used
exec.evalsrc/rules.js: … { id: 'MCP003', title: 'Use of eval() / dynamic code execution', severit…
Overall 69/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON
Other servers that do what MCP Customs does
- SPARDAAI writes. SPARDA proves. Deterministic, offline security gate for AI edits.not reviewedGrowingA
- PentestOffline methodology engine for authorized penetration testing, CTF, and security research.not reviewedGrowingB
- MCP Safety WardenMCP proxy adding security scanning, behavioral profiling, risk gating, and safe tool call execution.not reviewedGrowingB