Mmcp.market

Is CodeInspectus MCP server safe?

Probably. Read the findings first.

C58/100grade C

Use with care. Some checks failed or could not be verified.

What to know before installing
  • highShell command built from a string (injection risk)

Public scan report

scanner v0.1.9 · 2026-09-20 · same rubric, same numbers if you re-run it

1 high2 medium
  • Code scan30 source files scanned3/25
  • Live reliabilityno gateway calls yet and no remote to proben/a
  • Tool poisoningtools not inspected (local package is not executed); not countedn/a
  • Auth qualitylocal package, no credentials required12/15
  • Maintenancelast push 13 days ago15/15
  • Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10

Findings (3)

  • mediumsubprocess with shell=Trueexec.shell-true
    detection-db/manifest.json: …", "name": "Command injection via shell=True (Python)", "kind": "sast", …
  • highShell command built from a string (injection risk)exec.shell-concat
    detection-db/opengrep-rules/security-baseline/injection.yaml: …"...", shell=True) - pattern: os.system("..." + ...) - pattern: os.system(f".…
  • mediumeval / new Function usedexec.eval
    detection-db/opengrep-rules/security-baseline/injection.yaml: … - pattern-either: - pattern: eval($X) - pattern: new Function(..…
Overall 58/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Other servers that do what CodeInspectus does

  • Reversecore MCP
    Security-first MCP server for reverse engineering, malware analysis, forensics, and SAST.
    B
  • MCPProxy
    Local-first MCP proxy with BM25 tool discovery, security scanning, quarantine & ~99% token savings
    B
  • SecHelix
    Evidence-first security review of authorized repositories. Read-only, root-confined, no shell.
    A

CodeInspectus reviews, tools and install