security
Security
Every MCP risk signal in one place — CVEs, tool safety, drift, naming, licenses. Heuristic: review signals, not verdicts.
45 CRITICAL
3626 HIGH
531 MEDIUM
1202 LOW
11 NONE
Capability drift: a tracked server gaining a permission, adding/removing a tool, rewriting a description, or losing verified status between captures — a review signal, not a verdict.
- HIGH Builder106/Halberdcode analysis flagged committed secret in Builder106/Halberd
- HIGH firerpa/lamdacode analysis flagged committed secret ×6, dynamic code execution ×2 in firerpa/lamda
- HIGH lastmile-ai/mcp-agentcode analysis flagged dynamic code execution ×4 in lastmile-ai/mcp-agent
- HIGH 0x4m4/hexstrike-aicode analysis flagged dynamic code execution in 0x4m4/hexstrike-ai
- HIGH mukul975/Anthropic-Cybersecurity-Skillscode analysis flagged hidden prompt content ×11, committed secret, dynamic code execution ×2 in mukul975/Anthropic-Cybersecurity-Skills
- HIGH flipped-aurora/gin-vue-admincode analysis flagged committed secret ×2 in flipped-aurora/gin-vue-admin
- HIGH jeecgboot/JeecgBootcode analysis flagged committed secret ×6, dynamic code execution ×8 in jeecgboot/JeecgBoot
- HIGH evilsocket/nervecode analysis flagged dynamic code execution ×7 in evilsocket/nerve
- HIGH koreainvestment/open-trading-apicode analysis flagged committed secret, dynamic code execution ×13 in koreainvestment/open-trading-api
- HIGH Eronred/aso-skillscode analysis flagged hidden prompt content in Eronred/aso-skills
- HIGH universal-tool-calling-protocol/code-modecode analysis flagged dynamic code execution ×2 in universal-tool-calling-protocol/code-mode
- HIGH skernelx/tavily-key-generatorcode analysis flagged dynamic code execution in skernelx/tavily-key-generator
- HIGH lorryjovens-hub/claude-code-rustcode analysis flagged committed secret ×3 in lorryjovens-hub/claude-code-rust
- HIGH szczyglis-dev/py-gptcode analysis flagged dynamic code execution in szczyglis-dev/py-gpt
- HIGH superglue-ai/supergluecode analysis flagged dynamic code execution ×6 in superglue-ai/superglue
- HIGH heshengtao/comfyui_LLM_partycode analysis flagged hidden prompt content ×2, dynamic code execution ×2 in heshengtao/comfyui_LLM_party
- HIGH Jpisnice/shadcn-ui-mcp-servercode analysis flagged dynamic code execution in Jpisnice/shadcn-ui-mcp-server
- HIGH parcadei/Continuous-Claude-v3code analysis flagged dynamic code execution ×6 in parcadei/Continuous-Claude-v3
- HIGH joeseesun/qiaomu-anything-to-notebooklmcode analysis flagged dynamic code execution in joeseesun/qiaomu-anything-to-notebooklm
- HIGH 53AI/53AIHubcode analysis flagged committed secret ×4, dynamic code execution ×17 in 53AI/53AIHub
- HIGH cporter202/API-mega-listcode analysis flagged hidden prompt content ×3 in cporter202/API-mega-list
- HIGH sultannaufal/puppeteer-mcp-servercode analysis flagged dynamic code execution in sultannaufal/puppeteer-mcp-server
- HIGH shaharia-lab/mcp-frontendcode analysis flagged committed secret in shaharia-lab/mcp-frontend
- HIGH Galbaz1/video-research-mcpcode analysis flagged hidden prompt content ×2 in Galbaz1/video-research-mcp
- HIGH capiscio/a2a-demoscode analysis flagged dynamic code execution in capiscio/a2a-demos