Tool safety

tool-definition scan inferred

MCP-native tool-safety findings (tool poisoning, exfiltration combos, name shadowing, benign-dangerous tools, unconstrained schemas) from pure heuristics, newest-detected first; switch to the severity worklist to triage by impact — every row is a review signal with its evidence, never a verdict.

tool-safety findings 25 shown · newest first
sort recent severity
  • dangerous code 4516H 5293M 21948L
  • exfiltration combo 111H 650M 3467L
  • toxic flow (lethal trifecta) 64H 3147M
  • tool shadowing 399H 257M
  • purpose mismatch 277M 125L
  • hidden prompt content 145H 37L
  • rug pull 3H 86M
  • tool poisoning 14H 30M
  • cross-server steering 14M
  • loose schema 5M
  1. MEDIUM dangerous code shiplightai dynamic exec: new Function()
  2. LOW dangerous code shiplightai env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke
  3. LOW dangerous code shiplightai env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke
  4. LOW dangerous code shiplightai env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke
  5. LOW dangerous code shiplightai env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke
  6. MEDIUM toxic flow (lethal trifecta) @atlassian-dc-mcp/jira lethal trifecta reachable across this server's tool + source surface: private-data access + untrusted-content ingestion + network exfil (a leg is proven only in the analyzed source)
  7. HIGH dangerous code @browserstack/mcp-server obfuscated payload: dynamic require()/import()
  8. MEDIUM toxic flow (lethal trifecta) @browserstack/mcp-server lethal trifecta reachable across this server's tools: private-data access + untrusted-content ingestion + network exfil
  9. LOW exfiltration combo @browserstack/mcp-server sensitive read and network capabilities split across this server's tools
  10. MEDIUM dangerous code @testsprite/testsprite-mcp dynamic exec: new Function()
  11. MEDIUM dangerous code elysia-mcp dynamic exec: new Function()
  12. HIGH dangerous code @mcp-use/modelcontextprotocol-sdk credential logged in 2 file(s)
  13. MEDIUM toxic flow (lethal trifecta) @cyanheads/mcp-ts-core lethal trifecta reachable across this server's tool + source surface: private-data access + untrusted-content ingestion + network exfil (a leg is proven only in the analyzed source)
  14. HIGH dangerous code samuelgursky/davinci-resolve-mcp committed secret: Anthropic key · obfuscated payload: dynamic require()/import()
  15. LOW exfiltration combo samuelgursky/davinci-resolve-mcp sensitive read and network capabilities split across this server's tools
  16. MEDIUM dangerous code @hasna/prompts dynamic exec: new Function()
  17. MEDIUM toxic flow (lethal trifecta) @hasna/prompts lethal trifecta reachable across this server's tool + source surface: private-data access + untrusted-content ingestion + network exfil (a leg is proven only in the analyzed source)
  18. MEDIUM dangerous code clawdi dynamic exec: new Function()
  19. MEDIUM dangerous code AgentsKit-io/doc-bridge dynamic exec: new Function()
  20. HIGH dangerous code campfirein/byterover-cli obfuscated payload: dynamic require()/import()
  21. MEDIUM toxic flow (lethal trifecta) campfirein/byterover-cli lethal trifecta reachable across this server's tool + source surface: private-data access + untrusted-content ingestion + network exfil (a leg is proven only in the analyzed source)
  22. LOW dangerous code campfirein/byterover-cli env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke
  23. LOW dangerous code @sellable/install env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke
  24. LOW dangerous code @sellable/install env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke
  25. LOW dangerous code @sellable/install env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke