Mmcp.market

Is Have I Been Pwned MCP server safe?

Probably. Read the findings first.

C57/100grade C

Use with care. Some checks failed or could not be verified.

What to know before installing
  • highWrite-action tools reachable without authentication

Public scan report

scanner v0.1.9 · 2026-09-25 · same rubric, same numbers if you re-run it

1 high1 low
  • –Code scanremote-only server, no package to scann/a
  • Live reliabilityremote reachable in 429ms20/20
  • Tool poisoning17 tool descriptions checked15/15
  • Auth qualityopen endpoint exposes 3 write-action tools with no auth3/15
  • Maintenanceno repository listed3/15
  • Maintainer identityno repository or website to verify2/10

Findings (2)

  • highWrite-action tools reachable without authenticationauth.open-write
  • lowNo source repository listedmaint.no-repo
Overall 57/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Other servers that do what Have I Been Pwned does

  • OpenOSINT
    AI-powered OSINT agent & MCP server. 16 tools: email, breach, IP, WHOIS, DNS, Shodan, GitHub & more.
    C
  • MCP
    20 domain recon tools for AI agents: DNS, SSL, headers, email, subdomains, lookalikes, changes.
    A
  • Shipmail
    Shipmail MCP server for AI agent custom-domain email inboxes with REST API and webhooks.
    A

Have I Been Pwned reviews, tools and install