Is Jshookmcp MCP server safe?
Probably. Read the findings first.
Use with care. Some checks failed or could not be verified.
Public scan report
scanner v0.1.9 · 2026-09-27 · same rubric, same numbers if you re-run it
3 medium
- Code scan159 source files scanned10/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancelast push 0 days ago15/15
- Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10
Findings (3)
- mediumnpm install lifecycle script present
install.script - mediumeval / new Function used
exec.evaldist/ConsoleMonitor-DykL3IAw.mjs: … console.log('[ScriptMonitor] eval() called with code:', typeof… - mediumnpm install lifecycle script present
install.scriptpackage.json: …shOnly": "corepack pnpm run check", "postinstall": "node scripts/postinstall.cjs", "in…
Overall 69/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON
Other servers that do what Jshookmcp does
- Reddit BuddyReddit browser for AI assistants. Browse without API keys; add credentials for search and analysis.not reviewedEstablishedA
- SeleniumBase MCPStealthy browser automation, testing, and web-scraping via CDP Mode.not reviewedWidely usedA
- AIHawkAI browser agent: browses, clicks, types, and reads real web pages from plain-English instructions.not reviewedWidely usedA