Mmcp.market

grim-mcp

by AbduljabbarBXR·io.github.AbduljabbarBXR/grim-mcp·v0.5.0

Security audit for AI agents: code, deps, exposure, secrets, drift, SBOM, and IoC.

F26/100grade F
What users say
No reviews yet
Be the first
Safety scan
F26/100

full report

Adoption
New

467 downloads/wk

Blocked at the gateway.Blocked at the gateway. A critical finding or a dead endpoint.

Reviews

Write one

Nobody has reviewed grim-mcp yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

Tools

Tool lists for local packages are only visible after install.

Public scan report

scanner v0.1.3 · 2026-09-19 · same rubric, same numbers if you re-run it

2 high4 medium
  • Code scan33 source files scanned; 32 source files scanned0/25
  • Live reliabilityno gateway calls yet and no remote to proben/a
  • Tool poisoningtools not inspected (local package is not executed); not countedn/a
  • Auth qualitylocal package, no credentials required12/15
  • Maintenancerepository not readable: repo not found3/15
  • Maintainer identityno repository or website to verify2/10

Findings (6)

  • highcurl | sh in a scriptinstall.curl-pipe
    python/grim/core/attack.py: … Tool Transfer"), (("piped shell", "curl | sh"), "T1059.004", "Command and Scripting …
  • mediumsubprocess with shell=Trueexec.shell-true
    python/grim/core/fixplan.py: …fe_load(", line, count=1), False # shell=True with untrusted input -> disable shell e…
  • mediumeval / new Function usedexec.eval
    python/grim/engines/codepatterns.py: …\beval\s*\("), "high", "eval() usage", "eval executes arbitra…
  • highcurl | sh in a scriptinstall.curl-pipe
    grim-mcp-0.5.0/src/grim/core/attack.py: … Tool Transfer"), (("piped shell", "curl | sh"), "T1059.004", "Command and Scripting …
  • mediumsubprocess with shell=Trueexec.shell-true
    grim-mcp-0.5.0/src/grim/core/fixplan.py: …fe_load(", line, count=1), False # shell=True with untrusted input -> disable shell e…
  • mediumeval / new Function usedexec.eval
    grim-mcp-0.5.0/src/grim/engines/codepatterns.py: …\beval\s*\("), "high", "eval() usage", "eval executes arbitra…
Overall 26/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Install directly

Runs npx -y grim-mcp on your machine. Read the scan report first; the gateway never runs local packages.

claude mcp add grim-mcp -- npx -y grim-mcp
Add to Cursor

Alternatives to grim-mcp

Same job from other publishers, ranked by rating then adoption.

See all →
  • MCPProxy
    Local-first MCP proxy with BM25 tool discovery, security scanning, quarantine & ~99% token savings
    B
  • dns-doctor
    Scan, fix, verify and monitor DNS: SPF, DMARC, DKIM, propagation, health, expiry. Validated fixes.
    A
  • Reversecore MCP
    Security-first MCP server for reverse engineering, malware analysis, forensics, and SAST.
    B
  • secobserve-mcp
    MCP server for SecObserve: triage findings, import scan reports and SBOMs, generate VEX.
    B
  • Draugr
    Security scanning for AI agents: SAST, SCA, secrets, IaC, DAST, ranked by real risk.
    A

More from AbduljabbarBXR