Mmcp.market

Is Palinode MCP server safe?

Probably. Read the findings first.

C66/100grade C

Use with care. Some checks failed or could not be verified.

Public scan report

scanner v0.1.8 · 2026-09-19 · same rubric, same numbers if you re-run it

2 medium
  • Code scan184 source files scanned; 184 source files scanned15/25
  • Live reliabilityno gateway calls yet and no remote to proben/a
  • Tool poisoningtools not inspected (local package is not executed); not countedn/a
  • Auth qualitystatic API keys via environment variables6/15
  • Maintenancelast push 1 days ago15/15
  • Maintainer identityregistry namespace matches repository owner7/10

Findings (2)

  • mediumsubprocess with shell=Trueexec.shell-true
    palinode-0.21.0/palinode/core/git_tools.py: …form is used deliberately — never ``shell=True``, never string-interpolated commands …
  • mediumsubprocess with shell=Trueexec.shell-true
    palinode-0.21.0/palinode/core/git_tools.py: …form is used deliberately — never ``shell=True``, never string-interpolated commands …
Overall 66/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Other servers that do what Palinode does

  • Agent Memory
    Git-native project memory for AI coding agents: Markdown source of truth, reviewable, secret-safe.
    A
  • Nexusmem
    Local-first memory for AI coding agents: shell history with exit codes, git diffs, docs, MCP.
    A
  • memgit
    Git for AI memory — version-controlled, searchable context that persists across sessions
    B

Palinode reviews, tools and install