Tool safety
tool-definition scan inferred
MCP-native tool-safety findings (tool poisoning, exfiltration combos, name shadowing, benign-dangerous tools, unconstrained schemas) from pure heuristics, newest-detected first; switch to the severity worklist to triage by impact — every row is a review signal with its evidence, never a verdict.
- dangerous code 4516H 5293M 21948L
- exfiltration combo 111H 650M 3467L
- toxic flow (lethal trifecta) 64H 3147M
- tool shadowing 399H 257M
- purpose mismatch 277M 125L
- hidden prompt content 145H 37L
- rug pull 3H 86M
- tool poisoning 14H 30M
- cross-server steering 14M
- loose schema 5M
- MEDIUM dangerous code shiplightai dynamic exec: new Function()
- LOW dangerous code shiplightai env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke
- LOW dangerous code shiplightai env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke
- LOW dangerous code shiplightai env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke
- LOW dangerous code shiplightai env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke
- MEDIUM toxic flow (lethal trifecta) @atlassian-dc-mcp/jira lethal trifecta reachable across this server's tool + source surface: private-data access + untrusted-content ingestion + network exfil (a leg is proven only in the analyzed source)
- HIGH dangerous code @browserstack/mcp-server obfuscated payload: dynamic require()/import()
- MEDIUM toxic flow (lethal trifecta) @browserstack/mcp-server lethal trifecta reachable across this server's tools: private-data access + untrusted-content ingestion + network exfil
- LOW exfiltration combo @browserstack/mcp-server sensitive read and network capabilities split across this server's tools
- MEDIUM dangerous code @testsprite/testsprite-mcp dynamic exec: new Function()
- MEDIUM dangerous code elysia-mcp dynamic exec: new Function()
- HIGH dangerous code @mcp-use/modelcontextprotocol-sdk credential logged in 2 file(s)
- MEDIUM toxic flow (lethal trifecta) @cyanheads/mcp-ts-core lethal trifecta reachable across this server's tool + source surface: private-data access + untrusted-content ingestion + network exfil (a leg is proven only in the analyzed source)
- HIGH dangerous code samuelgursky/davinci-resolve-mcp committed secret: Anthropic key · obfuscated payload: dynamic require()/import()
- LOW exfiltration combo samuelgursky/davinci-resolve-mcp sensitive read and network capabilities split across this server's tools
- MEDIUM dangerous code @hasna/prompts dynamic exec: new Function()
- MEDIUM toxic flow (lethal trifecta) @hasna/prompts lethal trifecta reachable across this server's tool + source surface: private-data access + untrusted-content ingestion + network exfil (a leg is proven only in the analyzed source)
- MEDIUM dangerous code clawdi dynamic exec: new Function()
- MEDIUM dangerous code AgentsKit-io/doc-bridge dynamic exec: new Function()
- HIGH dangerous code campfirein/byterover-cli obfuscated payload: dynamic require()/import()
- MEDIUM toxic flow (lethal trifecta) campfirein/byterover-cli lethal trifecta reachable across this server's tool + source surface: private-data access + untrusted-content ingestion + network exfil (a leg is proven only in the analyzed source)
- LOW dangerous code campfirein/byterover-cli env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke
- LOW dangerous code @sellable/install env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke
- LOW dangerous code @sellable/install env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke
- LOW dangerous code @sellable/install env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke