Tool safety
tool-definition scan inferred
MCP-native tool-safety findings (tool poisoning, exfiltration combos, name shadowing, benign-dangerous tools, unconstrained schemas) from pure heuristics, newest-detected first; switch to the severity worklist to triage by impact — every row is a review signal with its evidence, never a verdict.
- dangerous code 4230H 4945M 21716L
- exfiltration combo 109H 638M 3331L
- toxic flow (lethal trifecta) 63H 3057M
- tool shadowing 391H 249M
- purpose mismatch 275M 117L
- hidden prompt content 141H 36L
- rug pull 4H 84M
- tool poisoning 14H 30M
- cross-server steering 13M
- loose schema 5M
- MEDIUM toxic flow (lethal trifecta) @agentmemory/mcp lethal trifecta reachable across this server's tools: private-data access + untrusted-content ingestion + network exfil
- LOW exfiltration combo @agentmemory/mcp sensitive read and network capabilities split across this server's tools
- MEDIUM dangerous code whyymj/page-agent-sdk dynamic exec: new Function()
- MEDIUM purpose mismatch whyymj/page-agent-sdk · subagents benign-looking name carries shell
- MEDIUM toxic flow (lethal trifecta) kubernetes-mcp-server lethal trifecta reachable across this server's tools: private-data access + untrusted-content ingestion + network exfil
- MEDIUM exfiltration combo kubernetes-mcp-server · nodes_stats_summary single tool reads + sends: fs, net
- MEDIUM dangerous code tidewave dynamic exec: new Function()
- LOW exfiltration combo DeusData/codebase-memory-mcp sensitive read and network capabilities split across this server's tools
- MEDIUM dangerous code openapi-mcp-generator dynamic exec: eval()
- MEDIUM dangerous code figma-console-mcp dynamic exec: eval()
- MEDIUM toxic flow (lethal trifecta) figma-console-mcp lethal trifecta reachable across this server's tool + source surface: private-data access + untrusted-content ingestion + network exfil (a leg is proven only in the analyzed source)
- MEDIUM dangerous code @foldkit/devtools-mcp dynamic exec: new Function()
- LOW dangerous code @sellable/install env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke
- LOW dangerous code @sellable/install env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke
- LOW dangerous code @sellable/install env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke
- LOW dangerous code @sellable/install env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke
- MEDIUM dangerous code @hasna/attachments dynamic exec: new Function()
- MEDIUM toxic flow (lethal trifecta) agentmail-mcp lethal trifecta reachable across this server's tool + source surface: private-data access + untrusted-content ingestion + network exfil (a leg is proven only in the analyzed source)
- LOW dangerous code agent-nuvira env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke
- LOW dangerous code agent-nuvira env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke
- LOW dangerous code agent-nuvira env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke
- LOW dangerous code agent-nuvira env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke
- LOW dangerous code agent-nuvira env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke
- LOW dangerous code agent-nuvira env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke
- LOW dangerous code agent-nuvira env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke