Is SDK MCP server safe?
Yes, with the usual care.
Safe to use. Minor gaps such as a missing repository or slower maintenance.
No critical or high findings in the latest scan.
Public scan report
scanner v0.1.9 · 2026-09-27 · same rubric, same numbers if you re-run it
no findings
- Code scan163 source files scanned25/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitystatic API keys via environment variables6/15
- Maintenancelast push 40 days ago12/15
- Maintainer identityregistry namespace matches repository owner; website matches verified namespace9/10
Overall 80/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON
Other servers that do what SDK does
- SDKMemory + wallet for AI agents. Real payment rails, Agent FICO 300-850, Merkle audit, identity.not reviewedGrowingB
- PipRailBudget-bound x402 payment wallet for AI agents — pays HTTP 402 URLs, capped locally. No backend.not reviewedGrowingB
- AgentpayNon-custodial x402 payment MCP server for AI agents. Wallets and payments on 17 chains.not reviewedGrowingB