Is Token Optimizer MCP server safe?
Probably. Read the findings first.
Use with care. Some checks failed or could not be verified.
Public scan report
scanner v0.1.9 · 2026-09-19 · same rubric, same numbers if you re-run it
3 medium
- Code scan1333 source files scanned10/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancelast push 0 days ago15/15
- Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10
Findings (3)
- mediumnpm install lifecycle script present
install.script - mediumeval / new Function used
exec.evaldist/tools/code-analysis/smart-security.js: …, cwe: 'CWE-327', }, // eval() usage { id: 'unsafe-eval',… - mediumnpm install lifecycle script present
install.scriptpackage.json: … "!**/.env.*" ], "scripts": { "postinstall": "node scripts/postinstall.cjs", "ch…
Overall 69/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON
Other servers that do what Token Optimizer does
Visual Memory MCPLocal visual UI cache for AI agents using perceptual hashing + CLIP to cut vision token use.not reviewedEstablishedA