security

Security

Every MCP risk signal in one place — CVEs, tool safety, drift, naming, licenses. Heuristic: review signals, not verdicts.

Static code-analysis findings — hidden prompt content in shipped skill files, committed secrets, dynamic-exec sinks, and suspicious call-home endpoints — across the analyzed catalogue. Heuristic, pure, no code executed; every row deep-links to its source. Click a kind to filter.

analysis coverage38% of 17283 analyzable servers
6275 analyzed
297 re-analysis due
1444 not analyzable
9267 not yet analyzed
711 source gone

Running analyzer v17. The scanner changelog explains what each version detects and when it changed.

  1. HIGH dynamic exec@vpxa/aikitvm exec- [ ] **eval/Function prevention**: No dynamic code execution from user input (\`eval()\`, \`new Function()\`, \`vm.runInNewContext()\`)
  2. HIGH dynamic exec@vpxa/aikitnew Function()- [ ] **eval/Function prevention**: No dynamic code execution from user input (\`eval()\`, \`new Function()\`, \`vm.runInNewContext()\`)
  3. LOW token-logbrilliant-directories-mcpcredential in logconsole.log(` claude mcp add ${serverName} -- npx -y brilliant-directories-mcp --api-key ${apiKey} --url ${apiUrl}`);
  4. LOW skill-scriptaiwgsuspicious bundled scripteval "$(python3 -c "
  5. HIGH hidden promptaiwgskill: skill-exfilsecret→sink: -H "Authorization: token ${GITHUB_TOKEN}" \
  6. HIGH hidden promptaiwgskill: skill-exfilsecret→sink: ```bash
  7. HIGH hidden promptaiwgskill: skill-exfilsecret→sink: # Fallback to fanart.tv if CAA unavailable
  8. HIGH hidden promptaiwgskill: skill-exfilsecret→sink:
  9. HIGH hidden promptaiwgskill: skill-exfilsecret→sink: -H "Authorization: token ${GITHUB_TOKEN}" \
  10. HIGH hidden promptaiwgskill: skill-exfilsecret→sink: ```bash
  11. HIGH hidden promptaiwgskill: skill-exfilsecret→sink: -H "Authorization: token ${GITHUB_TOKEN}" \
  12. HIGH hidden promptaiwgskill: skill-exfilsecret→sink: ```bash
  13. HIGH hidden promptaiwgskill: skill-exfilsecret→sink: # Fallback to fanart.tv if CAA unavailable
  14. HIGH hidden promptaiwgskill: skill-exfilsecret→sink:
  15. MEDIUM suspicious endpointharness-mcp-v21.2.3.4" {list:{elements:[{cluster:'staging', url:'https://1.2.3.4'}, {cluster:'prod', url:'https://2.3.4.5'}]}}\n" +