Is Protect MCP server safe?
Probably. Read the findings first.
Use with care. Some checks failed or could not be verified.
What to know before installing
- highShell command built from a string (injection risk)
Public scan report
scanner v0.1.9 · 2026-09-27 · same rubric, same numbers if you re-run it
1 high1 medium
- Code scan37 source files scanned8/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancelast push 11 days ago15/15
- Maintainer identitynamespace and repository owner differ4/10
Findings (2)
- mediumeval / new Function used
exec.evaldist/chunk-SU2FZH7U.mjs: …ode, sch); const makeValidate = new Function(`${names_1.default.self}`, `${names_1.de… - highShell command built from a string (injection risk)
exec.shell-concatdist/index.js: … = await import("child_process"); execSync(`docker rm -f ${sandbox.id} 2>/dev/null`, { stdio: "pipe…
Overall 60/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON
Other servers that do what Protect does
- Emilia ProtocolExact-action approval for consequential agent actions: request, track, and verify signed receipts.not reviewedEstablishedB
- AuscaPay-per-call APIs and MCP services for agents, no accounts or keys, with verifiable receipts.not reviewedEstablishedB
Agoragentic Agent OS MCPTriptych OS (Agent OS) MCP for governed routing, receipts, and USDC settlement on Base.not reviewedEstablishedB