security
Security
Every MCP risk signal in one place — CVEs, tool safety, drift, naming, licenses. Heuristic: review signals, not verdicts.
45 CRITICAL
3648 HIGH
531 MEDIUM
1205 LOW
11 NONE
License hygiene: servers missing a license or carrying a strong-copyleft, non-commercial, or unrecognized one — informational, not part of the composite risk score.
- missing / unlicensed supergateway— no license declared —
- missing / unlicensed chedong/phpman— no license declared —
- unrecognized rozetyp/vuln-intel-mcpNOASSERTION
- unrecognized sailquery/niche-mcpNOASSERTION
- unrecognized Dakera-AI/dakera-deployNOASSERTION
- unrecognized G-Schumacher44/strata-ossNOASSERTION
- strong copyleft churik5/bulwark-mcpAGPL-3.0
- missing / unlicensed second-brain-factory/data-mcp— no license declared —
- missing / unlicensed Paul-Orlando/pinecone-mcp-server— no license declared —
- missing / unlicensed 7blacky7/synapse— no license declared —
- unrecognized AndreaBonn/my-team-ai-config-hubNOASSERTION
- unrecognized vulny-app/vulny-agent-scanNOASSERTION
- missing / unlicensed lexwhiting/settlegrid— no license declared —
- missing / unlicensed BatElPeretz/api-b2m— no license declared —
- missing / unlicensed desper1do/obsidian-mcp-server— no license declared —
- strong copyleft cbcoutinho/nextcloud-mcp-serverAGPL-3.0
- unrecognized vvka-141/pgmiNOASSERTION
- missing / unlicensed amitsingh2003/Synapse— no license declared —
- strong copyleft jaingxyz/personal-outlook-mcpAGPL-3.0
- unrecognized SukramJ/openccu-loomNOASSERTION
- missing / unlicensed stelis-dev/agent-q— no license declared —
- strong copyleft mdzio/ccu-ai-mcpGPL-3.0
- strong copyleft laszlopere/mcp-abacusGPL-3.0
- unrecognized gautamvarmadatla/mcpsafetywardenNOASSERTION
- strong copyleft NDDev-it-com/rldyour-mimocodeAGPL-3.0