Tool safety

tool-definition scan inferred

MCP-native tool-safety findings (tool poisoning, exfiltration combos, name shadowing, benign-dangerous tools, unconstrained schemas) from pure heuristics, newest-detected first; switch to the severity worklist to triage by impact — every row is a review signal with its evidence, never a verdict.

tool-safety findings 25 shown · newest first
sort recent severity
  • dangerous code 4230H 4945M 21716L
  • exfiltration combo 109H 638M 3331L
  • toxic flow (lethal trifecta) 63H 3057M
  • tool shadowing 391H 249M
  • purpose mismatch 275M 117L
  • hidden prompt content 141H 36L
  • rug pull 4H 84M
  • tool poisoning 14H 30M
  • cross-server steering 13M
  • loose schema 5M
  1. MEDIUM toxic flow (lethal trifecta) @agentmemory/mcp lethal trifecta reachable across this server's tools: private-data access + untrusted-content ingestion + network exfil
  2. LOW exfiltration combo @agentmemory/mcp sensitive read and network capabilities split across this server's tools
  3. MEDIUM dangerous code whyymj/page-agent-sdk dynamic exec: new Function()
  4. MEDIUM purpose mismatch whyymj/page-agent-sdk · subagents benign-looking name carries shell
  5. MEDIUM toxic flow (lethal trifecta) kubernetes-mcp-server lethal trifecta reachable across this server's tools: private-data access + untrusted-content ingestion + network exfil
  6. MEDIUM exfiltration combo kubernetes-mcp-server · nodes_stats_summary single tool reads + sends: fs, net
  7. MEDIUM dangerous code tidewave dynamic exec: new Function()
  8. LOW exfiltration combo DeusData/codebase-memory-mcp sensitive read and network capabilities split across this server's tools
  9. MEDIUM dangerous code openapi-mcp-generator dynamic exec: eval()
  10. MEDIUM dangerous code figma-console-mcp dynamic exec: eval()
  11. MEDIUM toxic flow (lethal trifecta) figma-console-mcp lethal trifecta reachable across this server's tool + source surface: private-data access + untrusted-content ingestion + network exfil (a leg is proven only in the analyzed source)
  12. MEDIUM dangerous code @foldkit/devtools-mcp dynamic exec: new Function()
  13. LOW dangerous code @sellable/install env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke
  14. LOW dangerous code @sellable/install env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke
  15. LOW dangerous code @sellable/install env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke
  16. LOW dangerous code @sellable/install env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke
  17. MEDIUM dangerous code @hasna/attachments dynamic exec: new Function()
  18. MEDIUM toxic flow (lethal trifecta) agentmail-mcp lethal trifecta reachable across this server's tool + source surface: private-data access + untrusted-content ingestion + network exfil (a leg is proven only in the analyzed source)
  19. LOW dangerous code agent-nuvira env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke
  20. LOW dangerous code agent-nuvira env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke
  21. LOW dangerous code agent-nuvira env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke
  22. LOW dangerous code agent-nuvira env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke
  23. LOW dangerous code agent-nuvira env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke
  24. LOW dangerous code agent-nuvira env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke
  25. LOW dangerous code agent-nuvira env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke