Is Snyk MCP server safe?
Yes, with the usual care.
Safe to use. Minor gaps such as a missing repository or slower maintenance.
No critical or high findings in the latest scan.
Public scan report
scanner v0.1.9 · 2026-09-27 · same rubric, same numbers if you re-run it
3 medium
- Code scan321 source files scanned10/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancelast push 7 days ago15/15
- Maintainer identityregistry namespace matches repository owner; GitHub account older than a year9/10
Findings (3)
- mediumnpm install lifecycle script present
install.script - mediumeval / new Function used
exec.evaldist/cli/231.index.js: …he policy this.wasmInstance.exports.eval(ctxAddr); // Retrieve the result …
- mediumnpm install lifecycle script present
install.scriptpackage.json: …t/", "test": "npx jest test/*", "postinstall": "node wrapper_dist/bootstrap.js exec" …
Overall 71/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON
Other servers that do what Snyk does
- MobiLoopGuarded AI mobile Appium testing, security scanning, verification, and fix-retest MCP tools.not reviewedGrowingA
WP HealthKitSecurity audits for WordPress plugins and themes — 62 verification layers, fix plans and SBOMs.not reviewedGrowingA- CrowdStrike Falcon MCP ServerConnects AI agents with CrowdStrike Falcon for security analysis and automation.not reviewedEstablishedA