
Is mtdt — Salesforce DevOps MCP server safe?
Yes, with the usual care.
Passed every safety check we run. Maintained, authenticated, reachable, clean scan.
No critical or high findings in the latest scan.
Public scan report
scanner v0.1.9 · 2026-09-27 · same rubric, same numbers if you re-run it
no findings
- –Code scanremote-only server, no package to scann/a
- Live reliabilityremote reachable in 327ms (auth required)20/20
- –Tool poisoningtools not inspected (endpoint requires auth); not countedn/a
- Auth qualityOAuth resource metadata advertised on 40115/15
- Maintenancelast push 0 days ago15/15
- Maintainer identitynamespace and repository owner differ; website matches verified namespace6/10
Overall 93/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON
Other servers that do what mtdt — Salesforce DevOps does
- Salesforce MetadataThe only Salesforce MCP with Agentforce, OmniStudio & DevOps Center tools — 228 total.not reviewedGrowingB
- sf-intelligence — Salesforce org intelligence for AI agentsOffline, read-only MCP knowledge base for one Salesforce org's metadata, deps & impact.not reviewedGrowingA
- SalesforceSalesforce CRM MCP server: accounts, contacts, opportunities, leads, tasks, and custom objectsnot reviewedGrowingA