security

Security

Every MCP risk signal in one place — CVEs, tool safety, drift, naming, licenses. Heuristic: review signals, not verdicts.

Static code-analysis findings — hidden prompt content in shipped skill files, committed secrets, dynamic-exec sinks, and suspicious call-home endpoints — across the analyzed catalogue. Heuristic, pure, no code executed; every row deep-links to its source. Click a kind to filter.

analysis coverage38% of 17283 analyzable servers
6275 analyzed
297 re-analysis due
1444 not analyzable
9267 not yet analyzed
711 source gone

Running analyzer v17. The scanner changelog explains what each version detects and when it changed.

  1. LOW skill fileclaude-all-configskill
  2. LOW skill fileclaude-all-configskill
  3. LOW skill fileclaude-all-configskill
  4. LOW skill fileclaude-all-configskill
  5. LOW skill fileclaude-all-configskill
  6. LOW skill fileclaude-all-configskill
  7. LOW skill fileclaude-all-configskill
  8. LOW skill fileclaude-all-configskill
  9. LOW skill fileclaude-all-configskill
  10. LOW skill fileclaude-all-configskill
  11. LOW skill fileclaude-all-configskill
  12. LOW skill fileclaude-all-configskill
  13. LOW skill fileclaude-all-configskill
  14. LOW skill fileclaude-all-configskill
  15. LOW skill fileclaude-all-configskill