Is NeuroStack MCP server safe?
Not recommended.
Hidden from default browsing. Significant findings or unreachable.
What to know before installing
- highRemote endpoint did not respond — TypeError: fetch failed
- highShell command built from a string (injection risk)
Public scan report
scanner v0.1.9 · 2026-09-23 · same rubric, same numbers if you re-run it
2 high2 medium
- Code scan4 source files scanned3/25
- Live reliabilityremote unreachable: TypeError: fetch failed0/20
- –Tool poisoningtools not inspected (endpoint requires auth); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancelast push 0 days ago15/15
- Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10
Findings (4)
- highRemote endpoint did not respond
reliability.unreachableTypeError: fetch failed
- mediumnpm install lifecycle script present
install.script - mediumnpm install lifecycle script present
install.scriptpackage.json: …/neurostack.js" }, "scripts": { "postinstall": "node postinstall.js", "preuninstal… - highShell command built from a string (injection risk)
exec.shell-concatpostinstall.js: …npm rebuild neurostack"); info(`uv: ${execSync(`"${uv}" --version`, { encoding: "utf8" }).t…
Overall 45/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON
Safer options for the same job
DocsMintCloud or self-hosted knowledge for AI agents: hybrid search, reranking, GraphRAG, scoped MCP tools.not reviewedEstablishedA- MisakanetFailure-memory layer for coding agents: search evidence-rated failure lessons by error text.not reviewedEstablishedA
- MarmUniversal MCP Server with advanced AI memory capabilities and semantic search.not reviewedEstablishedA